PkgRadar

npm · registry.npmjs.org

yarn-audit-fix

Credential file access: matched ".npmrc"

Why PkgRadar flagged 11.0.0-snapshot.8

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/target/ts/stages.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
11.0.0-snapshot.8Review62026-06-09
11.0.0-snapshot.7Review62026-06-09
11.0.0-snapshot.6Review62026-06-05
11.0.0-snapshot.5Review62026-06-02
11.0.0-snapshot.4Review62026-05-31
11.0.0-snapshot.3Review62026-05-31
11.0.0-snapshot.2Review62026-05-31
11.0.0-snapshot.1Review62026-05-31
11.0.0-snapshot.0Review62026-05-31
10.1.0Review42026-05-31
10.1.1Review42026-05-31

Block this in CI

PkgRadar gates yarn-audit-fix (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]