PkgRadar

Package evidence

@hmcts/[email protected]

Credential file access: matched ".azure"

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
691
Versions published
29Mature · −50% score
First published
Apr 2025
Publisher
GitHub ActionsTrusted automation · −70% score

Effective trust discount applied: 70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@hmcts/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@hmcts/[email protected]"],"fail_on":"review"}'
Artifact bytes39,988
Previous version0.0.29
Published2026-05-08T15:05:42.956Z
SHA-256418ddcd8102b0b65edce11881aab381ddd0dda5b9e8c8fa990ba74dd28daf3b8

Why flagged

What the scanner saw

Credential file access: matched ".azure"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
1Score
0.0.30Version
Status history (1 event)
  1. newavailable · risk review · score 1 · status changed

Evidence

Static findings

1 static · 0 from release diff · showing high-signal first.

No high-signal findings — see all findings below.

Show all 1 findings (low-signal and informational)
SeverityKindPathDetailPoints
lowCredential file accesspackage/dist/helmet/index.jsmatched ".azure"5

Manifest

Package metadata

Scripts12
  • audit:checkyarn npm audit --recursive --environment production --json > yarn-known-issues-current || true && jq -s '[.[] | select(.type=="auditAdvisory") | .data.advisory.id] | sort' yarn-known-issues-current > current-ids.json && jq -s '[.[] | select(.type=="auditAdvisory") | .data.advisory.id] | sort' yarn-known-issues > known-ids.json && diff -q known-ids.json current-ids.json || (echo '❌ New vulnerabilities detected. Please review.' && exit 1)
  • audit:saveyarn npm audit --recursive --environment production --json > yarn-known-issues || true
  • buildyarn clean && tsc && cp src/*.d.ts dist/
  • check:exportsnode scripts/validate-export-targets.cjs
  • check:exports:esmnode scripts/smoke-test-exports.mjs
  • check:pack-shapenode scripts/validate-pack-shape.cjs
  • cleanrm -rf dist
  • linteslint ./src --ext .ts && yarn prettier
  • pack:localfind . -maxdepth 1 -type f -name 'hmcts-opal-frontend-common-node-*.tgz' -delete && npm_config_cache=${TMPDIR:-/tmp}/npm-cache-opal-common-node npm pack
  • prepackyarn build
  • prettierprettier --check "./src/**/*.{ts,js,json}"
  • prettier:fixprettier --write "./src/**/*.{ts,js,json}"
Dependencies20
  • @azure/msal-browser^5.0.0
  • @hmcts/info-provider^1.1.0
  • @hmcts/nodejs-healthcheck^1.8.5
  • @hmcts/nodejs-logging^4.0.4
  • @hmcts/properties-volume^1.1.0
  • applicationinsights~2.9.6
  • axios^1.6.2
  • body-parser^2.0.0
  • config^4.0.0
  • connect-redis^9.0.0
  • cookie-parser^1.4.6
  • csrf-csrf^4.0.0
  • express^5.0.0
  • express-session^1.17.3
  • helmet^8.0.0
  • http-proxy-middleware^4.0.0
  • luxon^3.4.3
  • redis^5.0.0
  • session-file-store^1.5.0
  • xml2js^0.6.2