PkgRadar

npm · registry.npmjs.org

create-swdg-app

Credential File Packaged: package/templates/car-records-management-system/server/.env

Why PkgRadar flagged 1.2.5

SeveritySignalEvidence
highCredential File Packagedpackage/templates/car-records-management-system/server/.env · package/templates/car-records-management-system/server/.env
highCredential File Packagedpackage/templates/employee-management-system/server/.env · package/templates/employee-management-system/server/.env
highCredential File Packagedpackage/templates/employee-position-management-system/server/.env · package/templates/employee-position-management-system/server/.env
highCredential File Packagedpackage/templates/library-management-system/server/.env · package/templates/library-management-system/server/.env
highCredential File Packagedpackage/templates/shipment-management-system/server/.env · package/templates/shipment-management-system/server/.env
highCredential File Packagedpackage/templates/slot-car-management-system/server/.env · package/templates/slot-car-management-system/server/.env
highCredential File Packagedpackage/templates/stock-manament-system/server/.env · package/templates/stock-manament-system/server/.env
highCredential File Packagedpackage/templates/warehouse-management-system/server/.env · package/templates/warehouse-management-system/server/.env
highCredential File Packagedpackage/templates/web-solution-dab-enterprise/back-end/.env · package/templates/web-solution-dab-enterprise/back-end/.env
highCredential File Packagedpackage/templates/web-vehicle-reservation-system/server/.env · package/templates/web-vehicle-reservation-system/server/.env

Scanned versions

VersionVerdictScoreScanned (UTC)
1.2.5High risk1002026-06-04
1.2.4High risk1002026-06-04
1.2.3High risk1002026-06-04

Block this in CI

PkgRadar gates create-swdg-app (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]