PkgRadar

npm · registry.npmjs.org

github-router

Credential file access: matched "GITHUB_TOKEN"

Why PkgRadar flagged 0.3.87

SeveritySignalEvidence
mediumCredential file accessmatched "GITHUB_TOKEN" · package/dist/main.js
mediumCredential file accessmatched "github_token" · package/dist/paths-DWVKYv16.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.87Review62026-06-16
0.3.110Review32026-06-16
0.3.82Review62026-06-11
0.3.74Review62026-06-11
0.3.73Review62026-06-07
0.3.72Review62026-06-06
0.3.71Review62026-06-05
0.3.68Review62026-06-04
0.3.66Review62026-06-04
0.3.52Review62026-06-03
0.3.45Low risk02026-06-03
0.3.44Low risk02026-06-02
0.3.43Low risk02026-06-02
0.3.42Low risk02026-06-01
0.3.41Low risk02026-06-01
0.3.40Low risk02026-05-30
0.3.39Low risk02026-05-30
0.3.38Low risk02026-05-29
0.3.37Review62026-05-29
0.3.36Review62026-05-29
0.3.35Review62026-05-29
0.3.33Review62026-05-27
0.3.34Review62026-05-27
0.3.31Review62026-05-25
0.3.30Review822026-05-24
0.3.29Review822026-05-24
0.3.27Review622026-05-24
0.3.28Review622026-05-24

Block this in CI

PkgRadar gates github-router (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]