PkgRadar

npm · registry.npmjs.org

azdo-cli

Credential file access: matched ".azure"

Why PkgRadar flagged 0.5.0-019-fix-pr-command.324

SeveritySignalEvidence
highCredential file accessmatched ".azure" · package/dist/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.0-024-azdo-pipeline.405Low risk02026-06-03
0.5.0-024-azdo-pipeline.407Low risk02026-06-03
0.5.0-022-version-update-check.384Low risk02026-06-03
0.10.0-develop.386Low risk02026-06-03
0.5.0-022-version-update-check.378Low risk02026-06-01
0.5.0-022-version-update-check.379Low risk02026-06-01
0.5.0-021-download-markdown-images.371Low risk02026-06-01
0.10.0-develop.373Low risk02026-06-01
0.5.0-021-download-markdown-images.367Low risk02026-06-01
0.5.0-021-download-markdown-images.365Low risk02026-06-01
0.10.0-develop.348Low risk02026-06-01
0.5.0-019-fix-pr-command.346Low risk02026-06-01
0.5.0-019-fix-pr-command.342Low risk02026-05-29
0.5.0-019-fix-pr-command.344Low risk02026-05-29
0.5.0-020-auth-docs-sync.326Low risk02026-05-29
0.5.0-020-auth-docs-sync.327Low risk02026-05-29
0.5.0-020-auth-docs-sync.325Low risk02026-05-29
0.5.0-019-fix-pr-command.324Review302026-05-24
0.5.0-019-fix-pr-command.323Review302026-05-24

Block this in CI

PkgRadar gates azdo-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]