PkgRadar

npm · registry.npmjs.org

scratch-l10n

Credential file access: matched "GITHUB_TOKEN"

Why PkgRadar flagged 6.1.84

SeveritySignalEvidence
highCredential file accessmatched "GITHUB_TOKEN" · package/scripts/update-translations.sh
mediumRemote Payloadmatched "iwr " · package/editor/interface/cy.json
mediumRemote Payloadmatched "iwr " · package/www/scratch-website.annual-report-2020-l10njson/cy.json
mediumRemote Payloadmatched "iwr " · package/www/scratch-website.annual-report-2021-l10njson/cy.json
mediumRemote Payloadmatched "iwr " · package/www/scratch-website.cookies-l10njson/cy.json
mediumRemote Payloadmatched "iwr " · package/www/scratch-website.dmca-l10njson/cy.json
mediumRemote Payloadmatched "iwr " · package/www/scratch-website.download-l10njson/cy.json
mediumRemote Payloadmatched "iwr " · package/www/scratch-website.faq-l10njson/cy.json
mediumRemote Payloadmatched "iwr " · package/www/scratch-website.general-l10njson/cy.json
mediumRemote Payloadmatched "iwr " · package/www/scratch-website.preview-l10njson/cy.json
mediumRemote Payloadmatched "iwr " · package/www/scratch-website.privacypolicy-l10njson/cy.json
mediumRemote Payloadmatched "iwr " · package/www/scratch-website.scratch_14-l10njson/cy.json

Scanned versions

VersionVerdictScoreScanned (UTC)
6.1.86Low risk02026-06-16
6.1.85Low risk02026-06-03
6.1.84Review1002026-05-25
6.1.82Review1002026-05-24
6.1.83Review1002026-05-24

Block this in CI

PkgRadar gates scratch-l10n (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]