PkgRadar

npm · registry.npmjs.org

git-truck

Credential file access: matched ".npmrc"

Scanned versions

VersionVerdictScoreScanned (UTC)
4.1.0Review12026-06-11
5.0.0Review12026-06-11
0.0.0-0e84865fReview22026-06-11
0.0.0-6ae693d4Review22026-06-10
0.0.0-64673564Review22026-06-08
0.0.0-15c35f38Review22026-06-08
0.0.0-203615ccReview22026-06-08
4.0.0Review152026-05-28
0.0.0-36bd09f5Review302026-05-28
0.0.0-60356c44Review72026-05-27
0.0.0-6f09c3d8Review72026-05-27
0.0.0-9f7a13feReview72026-05-27
0.0.0-1390853aReview72026-05-26
0.0.0-b3d4fe54Review72026-05-26
0.0.0-3d4e2a75Review72026-05-25
0.0.0-3dbd816fReview72026-05-25

Block this in CI

PkgRadar gates git-truck (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]