PkgRadar

npm · registry.npmjs.org

altair-graphql-core

Credential file access: matched ".aws"

Why PkgRadar flagged 8.5.3

SeveritySignalEvidence
highCredential file accessmatched ".aws" · package/build/cjs/request/handlers/app-sync.js
highCredential file accessmatched ".aws" · package/build/request/handlers/app-sync.js

Scanned versions

VersionVerdictScoreScanned (UTC)
8.5.8-alpha.d658484.0Low risk02026-06-06
8.5.7Low risk02026-06-06
8.5.8-alpha.69d1042.0Low risk02026-06-06
8.5.7-alpha.3025f1c.0Low risk02026-06-06
8.5.7-alpha.1edee7e.0Low risk02026-06-06
8.5.6Low risk02026-06-06
8.5.6-alpha.ae4b3e4.0Low risk02026-06-06
8.5.6-alpha.7af8728.0Low risk02026-06-06
8.5.5Low risk02026-06-04
8.5.6-alpha.cddec71.0Low risk02026-06-04
8.5.4Low risk02026-06-03
8.5.5-alpha.e317be6.0Low risk02026-06-03
8.5.4-alpha.e5f673c.0Low risk02026-06-03
8.5.3Review502026-05-24
8.5.4-alpha.8244b5b.0Review502026-05-24
8.5.3-alpha.430ede9.0Review502026-05-24
8.5.3-alpha.73edbb9.0Review502026-05-24

Block this in CI

PkgRadar gates altair-graphql-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]