PkgRadar

npm · registry.npmjs.org

@untemps/react-vocal

Credential file access: matched "GITHUB_TOKEN"

Why PkgRadar flagged 1.7.37

SeveritySignalEvidence
highCredential file accessmatched "GITHUB_TOKEN" · package/.github/workflows/publish.yml

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.0-beta.37Low risk02026-06-02
2.0.0-beta.36Low risk02026-06-02
2.0.0-beta.35Low risk02026-05-31
2.0.0-beta.34Low risk02026-05-31
2.0.0-beta.33Low risk02026-05-31
2.0.0-beta.32Low risk02026-05-31
2.0.0-beta.31Low risk02026-05-31
2.0.0-beta.30Low risk02026-05-31
2.0.0-beta.28Low risk02026-05-29
2.0.0-beta.29Low risk02026-05-29
2.0.0-beta.26Low risk02026-05-28
2.0.0-beta.24Low risk02026-05-27
2.0.0-beta.25Low risk02026-05-27
2.0.0-beta.21Low risk02026-05-26
2.0.0-beta.20Low risk02026-05-26
2.0.0-beta.19Low risk02026-05-25
2.0.0-beta.18Low risk02026-05-25
2.0.0-beta.17Low risk02026-05-24
2.0.0-beta.16Low risk02026-05-24
2.0.0-beta.15Low risk02026-05-24
2.0.0-beta.14Low risk02026-05-24
2.0.0-beta.13Low risk02026-05-24
2.0.0-beta.12Low risk02026-05-24
2.0.0-beta.11Low risk02026-05-24
2.0.0-beta.10Low risk02026-05-24
2.0.0-beta.9Low risk02026-05-24
1.7.37Review302026-05-24
2.0.0-beta.8Low risk02026-05-24

Block this in CI

PkgRadar gates @untemps/react-vocal (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @untemps/[email protected]