PkgRadar

npm · registry.npmjs.org

banguo-ui

Credential File Packaged: package/.npmrc

Why PkgRadar flagged 1.12.9

SeveritySignalEvidence
highCredential File Packagedpackage/.npmrc · package/.npmrc

Scanned versions

VersionVerdictScoreScanned (UTC)
1.12.9High risk172026-06-06
1.12.7High risk172026-06-06
1.12.8High risk172026-06-06

Block this in CI

PkgRadar gates banguo-ui (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]