PkgRadar

npm · registry.npmjs.org

capibara

Credential file access: matched ".npmrc"

Why PkgRadar flagged 1.1.15

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/node_modules_resp/global-prefix/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.3.59Low risk02026-06-11
1.1.15Review42026-06-11
1.3.57Low risk02026-06-11
1.3.58Low risk02026-06-11
1.3.56Low risk02026-06-09
1.3.53Low risk02026-06-09
1.3.54Low risk02026-06-09
1.3.55Low risk02026-06-09

Block this in CI

PkgRadar gates capibara (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]