PkgRadar

npm · registry.npmjs.org

@xylabs/toolchain

Credential file access: matched ".npmrc"

Why PkgRadar flagged 8.1.20

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/dist/lib/updo/fetchRegistryInfo.mjs
mediumCredential file accessmatched ".npmrc" · package/dist/lib/updo/index.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
8.1.20Review502026-06-10
8.1.19Review352026-06-09
8.1.18Review352026-06-09
8.1.17Review352026-06-09
8.1.16Review352026-06-05
8.1.15Review352026-06-03
8.1.13Review352026-06-03
8.1.14Review352026-06-03
8.1.12Review502026-06-02
8.1.10Review502026-06-02
8.1.11Review352026-06-02
8.1.9Review352026-06-02
8.1.8Review352026-05-29
8.1.7Review352026-05-29
8.1.5Review352026-05-29
8.1.6Review352026-05-29
8.1.3Review352026-05-28
8.1.4Review352026-05-28

Block this in CI

PkgRadar gates @xylabs/toolchain (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @xylabs/[email protected]