PkgRadar

npm · registry.npmjs.org

skuba

Credential File Packaged: package/template/express-rest-api/.env

Why PkgRadar flagged 16.2.0

SeveritySignalEvidence
highCredential File Packagedpackage/template/express-rest-api/.env · package/template/express-rest-api/.env
highCredential File Packagedpackage/template/koa-rest-api/.env · package/template/koa-rest-api/.env
highCredential File Packagedpackage/template/lambda-sqs-worker-cdk/.env · package/template/lambda-sqs-worker-cdk/.env
mediumCredential file accessmatched ".npmrc" · package/lib/cli/lint/internalLints/upgrade/patches/16.1.0/addSeekPackageRegistry.js

Scanned versions

VersionVerdictScoreScanned (UTC)
16.2.0Review372026-06-17
17.0.0-main-20260615230713Review372026-06-15
17.0.0-fix-docker-prune-20260615082053Review372026-06-15
17.0.0-main-20260615053143Review372026-06-15
17.0.0-main-20260615042621Review372026-06-15
16.2.0-use-vitest-globals-20260615002540Review372026-06-15
16.2.0-hoist-changesets-20260614023310Review372026-06-14
16.2.0-add-cdk-NodejsFunction-20260614035222Review372026-06-14
16.2.0-add-cdk-NodejsFunction-20260613141552Review372026-06-13
16.2.0-add-cdk-NodejsFunction-20260613135656Review372026-06-13
16.2.0-add-cdk-NodejsFunction-20260613134315Review372026-06-13
16.2.0-main-20260609014203Review332026-06-09
16.1.1-test-fix-lockfile-20260604014815Review402026-06-04
16.1.1-test-fix-lockfile-20260603070709Review402026-06-03
16.1.1-test-fix-lockfile-20260603053754Review402026-06-03
16.1.0Review402026-05-29
16.0.8Review402026-05-29
16.1.0-renovate-typescript-6.x-20260529051322Review402026-05-29

Block this in CI

PkgRadar gates skuba (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]