PkgRadar

PyPI · pypi.org

solace-agent-mesh

Credential File Packaged: solace_agent_mesh-1.28.2/client/webui/frontend/.npmrc

Why PkgRadar flagged 1.28.2

SeveritySignalEvidence
highCredential File Packagedsolace_agent_mesh-1.28.2/client/webui/frontend/.npmrc · solace_agent_mesh-1.28.2/client/webui/frontend/.npmrc
highCredential File Packagedsolace_agent_mesh-1.28.2/config_portal/frontend/.npmrc · solace_agent_mesh-1.28.2/config_portal/frontend/.npmrc
highCredential File Packagedsolace_agent_mesh-1.28.2/docs/.npmrc · solace_agent_mesh-1.28.2/docs/.npmrc

Scanned versions

VersionVerdictScoreScanned (UTC)
1.28.2High risk702026-06-04
1.28.1High risk702026-06-04
1.28.0High risk702026-06-02
1.27.1High risk702026-06-02
1.27.0High risk702026-06-02

Block this in CI

PkgRadar gates solace-agent-mesh (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi solace-agent-mesh==1.28.2