npm · registry.npmjs.org
skuba
Credential File Packaged: package/template/express-rest-api/.env
Why PkgRadar flagged 16.2.0
| Severity | Signal | Evidence |
|---|---|---|
| high | Credential File Packaged | package/template/express-rest-api/.env · package/template/express-rest-api/.env |
| high | Credential File Packaged | package/template/koa-rest-api/.env · package/template/koa-rest-api/.env |
| high | Credential File Packaged | package/template/lambda-sqs-worker-cdk/.env · package/template/lambda-sqs-worker-cdk/.env |
| medium | Credential file access | matched ".npmrc" · package/lib/cli/lint/internalLints/upgrade/patches/16.1.0/addSeekPackageRegistry.js |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
16.2.0 | Review | 37 | 2026-06-17 |
17.0.0-main-20260615230713 | Review | 37 | 2026-06-15 |
17.0.0-fix-docker-prune-20260615082053 | Review | 37 | 2026-06-15 |
17.0.0-main-20260615053143 | Review | 37 | 2026-06-15 |
17.0.0-main-20260615042621 | Review | 37 | 2026-06-15 |
16.2.0-use-vitest-globals-20260615002540 | Review | 37 | 2026-06-15 |
16.2.0-hoist-changesets-20260614023310 | Review | 37 | 2026-06-14 |
16.2.0-add-cdk-NodejsFunction-20260614035222 | Review | 37 | 2026-06-14 |
16.2.0-add-cdk-NodejsFunction-20260613141552 | Review | 37 | 2026-06-13 |
16.2.0-add-cdk-NodejsFunction-20260613135656 | Review | 37 | 2026-06-13 |
16.2.0-add-cdk-NodejsFunction-20260613134315 | Review | 37 | 2026-06-13 |
16.2.0-main-20260609014203 | Review | 33 | 2026-06-09 |
16.1.1-test-fix-lockfile-20260604014815 | Review | 40 | 2026-06-04 |
16.1.1-test-fix-lockfile-20260603070709 | Review | 40 | 2026-06-03 |
16.1.1-test-fix-lockfile-20260603053754 | Review | 40 | 2026-06-03 |
16.1.0 | Review | 40 | 2026-05-29 |
16.0.8 | Review | 40 | 2026-05-29 |
16.1.0-renovate-typescript-6.x-20260529051322 | Review | 40 | 2026-05-29 |
Block this in CI
pkgradar gate --ecosystem npm [email protected]