PkgRadar

npm · registry.npmjs.org

typeorm

Credential file access: matched ".aws"

Why PkgRadar flagged 1.0.0-nightly.20260525

SeveritySignalEvidence
highCredential file accessmatched ".aws" · package/browser/driver/postgres/PostgresQueryRunner.js
highCredential file accessmatched ".aws" · package/driver/postgres/PostgresQueryRunner.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.0-nightly.20260604Low risk02026-06-04
1.0.0-nightly.20260603Low risk02026-06-03
1.0.0-nightly.20260602Low risk02026-06-02
1.0.0-nightly.20260601Low risk02026-06-01
1.0.0-nightly.20260531Low risk02026-05-31
1.0.0-nightly.20260530Low risk02026-05-30
1.0.0-nightly.20260529Low risk02026-05-29
1.0.0-nightly.20260528Low risk02026-05-28
1.0.0-nightly.20260527Low risk02026-05-27
1.0.0-nightly.20260526Low risk02026-05-26
1.0.0-nightly.20260525Review502026-05-25
1.0.0-nightly.20260523Review502026-05-24
1.0.0-nightly.20260524Review502026-05-24

Block this in CI

PkgRadar gates typeorm (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]