PkgRadar

npm · registry.npmjs.org

@waron97/prbot

Credential file access: matched ".azure"

Why PkgRadar flagged 3.0.4

SeveritySignalEvidence
highCredential file accessmatched ".azure" · package/src/commands/autopr.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.1.3Low risk02026-06-04
3.1.4Low risk02026-06-04
3.1.2Low risk02026-06-04
3.1.1Low risk02026-05-31
3.1.0Low risk02026-05-30
3.0.5Low risk02026-05-28
3.0.4Review302026-05-26
3.0.3Review302026-05-25
3.0.2Review302026-05-25
3.0.1Review302026-05-25
2.8.0Review302026-05-24
3.0.0Review302026-05-24

Block this in CI

PkgRadar gates @waron97/prbot (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @waron97/[email protected]