PkgRadar

PyPI · pypi.org

pgwidgets-js

Credential File Packaged: pgwidgets_js-0.3.1/examples/electron/.npmrc

Why PkgRadar flagged 0.3.1

SeveritySignalEvidence
highCredential File Packagedpgwidgets_js-0.3.1/examples/electron/.npmrc · pgwidgets_js-0.3.1/examples/electron/.npmrc

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.1High risk352026-06-06

Block this in CI

PkgRadar gates pgwidgets-js (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi pgwidgets-js==0.3.1