PkgRadar

npm · registry.npmjs.org

reasonix

Credential file access: matched "id_rsa"

Why PkgRadar flagged 0.50.0

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.50.0 vs 0.49.0: "npm --prefix dashboard ci --ignore-scripts && npm --prefix desktop ci --ignore-scripts" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.7.0-rc.1Low risk02026-06-13
1.6.0-rc.1Low risk02026-06-13
1.5.0-rc.1Low risk02026-06-10
0.50.0High risk552026-06-10
1.4.0-rc.1Low risk02026-06-09
1.4.0-canary.3Low risk02026-06-08
1.4.0-canary.2Low risk02026-06-08
1.3.0-rc.1Low risk02026-06-07
1.2.0Low risk02026-06-05
1.2.0-rc.1Low risk02026-06-05
1.1.0Low risk02026-06-04
1.1.0-rc.1Low risk02026-06-04
1.0.0Low risk02026-06-03
1.0.0-rc1Low risk02026-06-03
0.53.1Review72026-05-30
0.52.0Review72026-05-30
0.50.1Review72026-05-30
0.54.2Review52026-05-29
0.54.0Review52026-05-29
0.53.2Review402026-05-27
0.51.0Review402026-05-25
0.49.0Review1392026-05-25

Related campaigns

Block this in CI

PkgRadar gates reasonix (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]