PkgRadar

npm · registry.npmjs.org

tychat-contracts

Credential file access: matched "NPM_TOKEN"

Why PkgRadar flagged 1.6.47

SeveritySignalEvidence
highCredential file accessmatched "NPM_TOKEN" · package/.github/workflows/publish-npm.yml

Scanned versions

VersionVerdictScoreScanned (UTC)
1.6.83Low risk02026-06-17
1.6.82Low risk02026-06-17
1.6.81Low risk02026-06-16
1.6.80Low risk02026-06-16
1.6.79Low risk02026-06-16
1.6.78Low risk02026-06-15
1.6.76Low risk02026-06-15
1.6.75Low risk02026-06-10
1.6.74Low risk02026-06-10
1.6.73Low risk02026-06-10
1.6.72Low risk02026-06-10
1.6.69Low risk02026-06-04
1.6.68Low risk02026-06-02
1.6.67Low risk02026-06-02
1.6.66Low risk02026-06-01
1.6.65Low risk02026-06-01
1.6.64Low risk02026-06-01
1.6.63Low risk02026-06-01
1.6.61Low risk02026-06-01
1.6.62Low risk02026-06-01
1.6.60Low risk02026-05-31
1.6.59Low risk02026-05-31
1.6.58Low risk02026-05-31
1.6.57Low risk02026-05-30
1.6.56Low risk02026-05-30
1.6.53Low risk02026-05-30
1.6.52Low risk02026-05-30
1.6.50Low risk02026-05-29
1.6.51Low risk02026-05-29
1.6.47Review302026-05-24
1.6.46Review302026-05-24
1.6.45Review302026-05-24
1.6.44Review302026-05-24

Related campaigns

Block this in CI

PkgRadar gates tychat-contracts (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]