PkgRadar

npm · registry.npmjs.org

@zigrivers/scaffold

Credential file access: matched ".aws"

Why PkgRadar flagged 3.27.0

SeveritySignalEvidence
highCredential file accessmatched ".aws" · package/dist/observability/engine/redact.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.34.1Low risk02026-06-11
3.34.0Low risk02026-06-08
3.33.7Low risk02026-06-08
3.33.6Low risk02026-06-08
3.33.5Low risk02026-06-05
3.33.4Low risk02026-06-05
3.33.3Low risk02026-06-03
3.33.2Low risk02026-06-03
3.33.1Low risk02026-06-02
3.33.0Low risk02026-05-31
3.32.1Low risk02026-05-31
3.32.0Low risk02026-05-31
3.31.1Low risk02026-05-31
3.31.0Low risk02026-05-31
3.30.0Low risk02026-05-31
3.29.0Low risk02026-05-30
3.27.0Review302026-05-24
3.28.0Review302026-05-24

Related campaigns

Block this in CI

PkgRadar gates @zigrivers/scaffold (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @zigrivers/[email protected]