PkgRadar

npm · registry.npmjs.org

windmill-client

Credential file access: matched ".Azure"

Why PkgRadar flagged 1.708.0

SeveritySignalEvidence
highCredential file accessmatched ".Azure" · package/dist/index.js
mediumRemote Payloadmatched "cUrl " · package/dist/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.728.0Low risk02026-06-16
1.727.0Low risk02026-06-16
1.726.1Low risk02026-06-15
1.726.0Low risk02026-06-15
1.725.1Low risk02026-06-15
1.725.0Low risk02026-06-15
1.724.0Low risk02026-06-15
1.723.0Low risk02026-06-11
1.722.0Low risk02026-06-11
1.721.0Low risk02026-06-09
1.720.0Low risk02026-06-08
1.719.0Low risk02026-06-06
1.718.0Low risk02026-06-05
1.717.1Low risk02026-06-04
1.717.0Low risk02026-06-04
1.716.0Low risk02026-06-03
1.715.0Low risk02026-06-03
1.714.1Low risk02026-06-02
1.714.0Low risk02026-06-02
1.713.1Low risk02026-06-01
1.713.0Low risk02026-05-31
1.712.0Low risk02026-05-28
1.711.0Low risk02026-05-26
1.710.1Low risk02026-05-26
1.710.0Low risk02026-05-26
1.709.0Low risk02026-05-25
1.708.0Review422026-05-24
1.707.0Review422026-05-24

Related campaigns

Block this in CI

PkgRadar gates windmill-client (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]