PkgRadar

npm · registry.npmjs.org

argusqa-os

Credential file access: matched "GITHUB_TOKEN"

Why PkgRadar flagged 9.7.4

SeveritySignalEvidence
highCredential file accessmatched "GITHUB_TOKEN" · package/src/utils/github-reporter.js

Scanned versions

VersionVerdictScoreScanned (UTC)
9.7.4Review212026-06-12
9.7.3Review302026-06-11
9.6.6Review302026-06-11
9.6.5Review212026-06-08
9.6.4Review302026-06-08
9.6.3Review212026-06-08
9.6.2Review212026-06-08
9.6.1Review212026-06-08
9.5.9Review302026-06-08
9.6.0Review302026-06-08
9.5.5Review212026-06-06
9.5.3Review302026-06-04
9.5.1Low risk02026-05-31
9.5.0Low risk02026-05-30
9.4.6Low risk02026-05-30
9.4.5Low risk02026-05-30
9.4.4Low risk02026-05-30
9.4.3Low risk02026-05-30
9.4.1Low risk02026-05-30
9.4.2Low risk02026-05-30
9.4.0Low risk02026-05-30
9.3.1Review352026-05-29
9.2.9Review352026-05-29
9.3.0Review352026-05-29
9.2.6Review352026-05-28
9.2.5Review352026-05-28
9.2.3Review352026-05-27
9.2.2Review352026-05-27

Block this in CI

PkgRadar gates argusqa-os (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]