PkgRadar

npm · registry.npmjs.org

forgemap

Credential file access: matched ".ssh"

Why PkgRadar flagged 0.1.0-dev.35-1e6da52

SeveritySignalEvidence
highCredential file accessmatched ".ssh" · package/dist/bin/forgemap.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.1-dev-main.54-85b5e29Low risk02026-06-08
0.4.1-dev.53-1d36daaLow risk02026-06-08
0.4.1-dev.52-d6b74c6Low risk02026-06-08
0.4.1-dev-main.51-e23c7d0Low risk02026-05-30
0.4.1-dev.50-2c04b38Low risk02026-05-30
0.4.1-dev.49-4804d8eLow risk02026-05-30
0.4.1-dev.47-aae639dLow risk02026-05-29
0.4.1-dev-main.48-b1e759eLow risk02026-05-29
0.4.0-dev.42-19c7093Low risk02026-05-27
0.4.0-dev-main.43-1758b5eLow risk02026-05-27
0.1.0-dev.39-7be8a05Low risk02026-05-25
0.1.0-dev-main.40-70e9f5aLow risk02026-05-25
0.1.0-dev-main.36-8c52303Low risk02026-05-25
0.1.0-dev.35-1e6da52Review302026-05-25
0.1.0-dev.34-313527bReview302026-05-25
0.1.0-dev-main.32-53be8b9Review302026-05-24
0.1.0-dev.31-22af2e3Review302026-05-24
0.1.0-dev-main.30-07643acReview302026-05-24

Block this in CI

PkgRadar gates forgemap (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]