PkgRadar

npm · registry.npmjs.org

heroku

Credential file access: matched ".ssh/"

Why PkgRadar flagged 11.6.0-beta.0

SeveritySignalEvidence
mediumCredential file accessmatched ".ssh/" · package/dist/commands/keys/add.js

Scanned versions

VersionVerdictScoreScanned (UTC)
11.6.0-beta.0Review32026-06-15
11.5.0Review32026-06-11
7.4.6Low risk02026-06-11
7.4.5Low risk02026-06-11
11.5.0-beta.0Review32026-06-11
11.5.0-alpha.8Review32026-06-09
11.5.0-alpha.6Review32026-06-04
11.5.0-alpha.5Review32026-06-02
11.4.1-beta.0Review72026-05-27
11.4.0Review72026-05-27
11.5.0-alpha.4Review72026-05-27

Block this in CI

PkgRadar gates heroku (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]
heroku — npm security scan | PkgRadar