npm · registry.npmjs.org
liftie
Credential file access: matched ".azure"
Why PkgRadar flagged 4.3.3
| Severity | Signal | Evidence |
|---|---|---|
| high | Credential file access | matched ".azure" · package/lib/resorts/big-sky/resort.json |
| high | Credential file access | matched ".azure" · package/lib/resorts/brighton/resort.json |
| high | Credential file access | matched ".azure" · package/lib/resorts/loon/resort.json |
| high | Credential file access | matched ".azure" · package/lib/resorts/pleasant-mountain/resort.json |
| high | Credential file access | matched ".azure" · package/lib/resorts/sugarloaf/resort.json |
| high | Credential file access | matched ".azure" · package/lib/resorts/sunday-river/resort.json |
| medium | Remote Payload | matched "curl " · package/lib/cli/fetch.js |
| medium | Remote Payload | matched "curl " · package/lib/cli/generate.js |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
4.3.3 | Review | 74 | 2026-05-24 |
4.3.4 | Review | 74 | 2026-05-24 |
Block this in CI
pkgradar gate --ecosystem npm [email protected]