PkgRadar

npm · registry.npmjs.org

runspec-node

Credential file access: matched ".ssh"

Why PkgRadar flagged 0.15.0

SeveritySignalEvidence
highCredential file accessmatched ".ssh" · package/dist/jump.js
highCredential file accessmatched ".ssh" · package/src/jump.ts
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/cli.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/runspec.toml
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/src/runspec.toml
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/src/cli.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.33.1Low risk02026-06-15
0.33.0Low risk02026-06-14
0.32.0Low risk02026-06-12
0.31.0Low risk02026-06-12
0.30.0Low risk02026-06-12
0.29.0Low risk02026-06-12
0.28.1Low risk02026-06-10
0.28.0Low risk02026-06-08
0.27.0Low risk02026-06-05
0.26.1Low risk02026-06-04
0.26.0Low risk02026-06-04
0.25.0Low risk02026-06-04
0.24.0Low risk02026-06-04
0.23.0Low risk02026-06-04
0.22.0Low risk02026-06-03
0.21.0Low risk02026-06-03
0.19.0Low risk02026-06-03
0.17.1Low risk02026-05-28
0.17.0Low risk02026-05-27
0.16.0Low risk02026-05-26
0.15.0Review742026-05-24
0.13.1Review742026-05-24
0.14.0Review742026-05-24

Related campaigns

Block this in CI

PkgRadar gates runspec-node (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]