PkgRadar

npm · registry.npmjs.org

coze-coding-dev-sdk

Credential file access: matched "AWS_ACCESS_KEY"

Why PkgRadar flagged 0.7.24

SeveritySignalEvidence
mediumCredential file accessmatched "AWS_ACCESS_KEY" · package/dist/cjs/cli/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.7.24Review212026-06-03
0.7.19-beta.19Review212026-06-03
0.7.19-beta.20Review212026-06-03
0.7.23Review302026-05-28
0.7.19-beta.18Review212026-05-28

Block this in CI

PkgRadar gates coze-coding-dev-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]