PkgRadar

npm · registry.npmjs.org

@upstash/vector

Credential file access: matched ".AWS"

Why PkgRadar flagged 0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260525005018

SeveritySignalEvidence
highCredential file accessmatched ".AWS" · package/dist/nodejs.js
highCredential file accessmatched ".AWS" · package/dist/nodejs.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260617005724Low risk02026-06-17
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260616010242Low risk02026-06-16
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260615005741Low risk02026-06-15
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260614005622Low risk02026-06-15
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260612005703Low risk02026-06-12
1.2.3Low risk02026-06-11
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260611005400Low risk02026-06-11
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260610005507Low risk02026-06-10
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260609004829Low risk02026-06-09
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260607005349Low risk02026-06-08
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260608005507Low risk02026-06-08
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260606005020Low risk02026-06-06
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260605005300Low risk02026-06-05
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260604010038Low risk02026-06-04
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260603010058Low risk02026-06-03
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260602005508Low risk02026-06-02
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260601005420Low risk02026-06-01
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260531005155Low risk02026-05-31
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260530004831Low risk02026-05-30
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260529005237Low risk02026-05-29
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260528004553Low risk02026-05-28
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260527004939Low risk02026-05-27
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260526004835Low risk02026-05-26
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260525005018Review502026-05-25
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260523004741Review502026-05-24
0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260524004842Review502026-05-24

Block this in CI

PkgRadar gates @upstash/vector (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @upstash/vector@0.0.0-ci.ad3ad721a1d5035c5a891830174cbba8bcd9d10d-20260525005018