PkgRadar

npm · registry.npmjs.org

n20-common-lib

Credential file access: matched "ID_RSA"

Why PkgRadar flagged 3.1.9

SeveritySignalEvidence
highCredential file accessmatched "ID_RSA" · package/src/plugins/Sign/Itrus/index.js
highCredential file accessmatched "ID_RSA" · package/src/plugins/Sign/Itrus/sign_3720.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.22.41Low risk02026-06-17
3.2.4Low risk02026-06-15
3.2.3Low risk02026-06-15
3.2.2Low risk02026-06-11
3.2.1Low risk02026-06-11
2.22.40Low risk02026-06-11
2.22.39Low risk02026-06-09
3.2.0Low risk02026-06-09
3.1.21Low risk02026-06-04
3.1.20Low risk02026-06-03
3.1.19Low risk02026-06-02
3.1.18Low risk02026-06-02
3.1.17Low risk02026-06-02
3.1.15Low risk02026-06-02
3.1.16Low risk02026-06-02
3.1.14Low risk02026-05-29
3.1.13Low risk02026-05-29
3.1.12Low risk02026-05-28
3.1.11Low risk02026-05-27
3.1.9Review502026-05-25
3.1.10Review502026-05-25

Related campaigns

Block this in CI

PkgRadar gates n20-common-lib (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]