PkgRadar

npm · registry.npmjs.org

scan-compromised

Credential file access: matched "GITHUB_TOKEN"

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.226Low risk02026-06-17
1.1.225Low risk02026-06-16
1.1.224Low risk02026-06-15
1.1.223Low risk02026-06-13
1.1.222Low risk02026-06-12
1.1.221Low risk02026-06-11
1.1.220Low risk02026-06-10
1.1.219Low risk02026-06-09
1.1.218Low risk02026-06-07
1.1.217Low risk02026-06-06
1.1.216Low risk02026-06-05
1.1.215Low risk02026-06-04
1.1.214Low risk02026-06-03
1.1.213Low risk02026-06-02
1.1.212Low risk02026-06-01
1.1.211Low risk02026-05-31
1.1.210Low risk02026-05-30
1.1.209Review12026-05-29
1.1.208Review12026-05-28
1.1.207Review12026-05-27
1.1.206Review102026-05-25
1.1.204Review422026-05-24
1.1.205Review422026-05-24

Block this in CI

PkgRadar gates scan-compromised (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]