PkgRadar

npm · registry.npmjs.org

medusa-dev-cli

Credential file access: matched ".npmrc"

Why PkgRadar flagged 2.15.6-preview-20260604042824

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/dist/local-npm-registry/publish-package.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.15.6-preview-20260604042824Review32026-06-04
2.15.6-preview-20260604003214Review32026-06-04
2.15.6-preview-20260603215704Review32026-06-03
2.15.6-preview-20260603191113Review32026-06-03
2.15.6-preview-20260603163110Review32026-06-03
2.16.0-snapshot-20260603131403Review32026-06-03
2.15.6-preview-20260603132452Review32026-06-03
2.15.6-preview-20260603103142Review32026-06-03
2.15.6-preview-20260603042847Review32026-06-03
2.15.6-preview-20260603073149Review32026-06-03
2.15.6-preview-20260603003142Review32026-06-03
2.15.6-preview-20260602215642Review32026-06-02
2.15.6-preview-20260602190553Review32026-06-02
2.15.6-preview-20260602163001Review32026-06-02
2.15.6-preview-20260602130418Review32026-06-02
2.15.6-preview-20260602102950Review32026-06-02
2.15.6-preview-20260602072904Review32026-06-02
2.15.6-preview-20260602042835Review32026-06-02
2.15.6-preview-20260602002651Review32026-06-02
2.15.6-preview-20260601215956Review32026-06-01
2.15.6-preview-20260601193424Review32026-06-01
2.15.6-preview-20260601164843Review32026-06-01
2.15.6-preview-20260601135003Review32026-06-01
2.15.6-preview-20260601104039Review32026-06-01
2.15.6-preview-20260601073416Review32026-06-01
2.15.5Review32026-05-29
2.15.5-preview-20260529071036Review32026-05-29
2.15.5-preview-20260529042707Review32026-05-29
2.15.5-preview-20260529002348Review32026-05-29
2.15.5-preview-20260528213549Review32026-05-29
2.15.5-preview-20260528130220Review32026-05-28
2.15.5-preview-20260528102332Review32026-05-28
2.15.5-preview-20260528071012Review32026-05-28
2.15.5-preview-20260528042528Review32026-05-28
2.15.5-preview-20260527213205Review32026-05-28
2.15.5-preview-20260528002022Review32026-05-28
2.15.5-preview-20260526070309Review32026-05-26
2.15.5-preview-20260526042351Review32026-05-26
2.15.5-preview-20260526002046Review32026-05-26
2.15.5-preview-20260525212304Review32026-05-25
2.15.5-preview-20260525182829Review32026-05-25
2.15.5-preview-20260525155625Review32026-05-25
2.15.5-preview-20260525130010Review32026-05-25
2.15.5-preview-20260525102758Review102026-05-25
2.15.5-preview-20260525072343Low risk02026-05-25
2.15.5-preview-20260525042800Review502026-05-25
2.15.5-preview-20260525002045Review502026-05-25
2.15.5-preview-20260524211621Review502026-05-24
2.15.5-preview-20260524181646Review502026-05-24
2.15.5-preview-20260524152218Review502026-05-24
2.15.5-preview-20260524121647Review502026-05-24
2.15.5-preview-20260524093424Review502026-05-24
2.15.5-preview-20260524065951Review502026-05-24
2.15.5-preview-20260524001925Review502026-05-24
2.15.5-preview-20260524042533Review502026-05-24

Block this in CI

PkgRadar gates medusa-dev-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]