What is the risk of committing .npmrc file and exposing to the world?
I have seen multiple projects committing .npmrc file along with rest of the files. Are the auth credentials npm credentials? What is the risk if an attacker gets hold of the credentials? As npm requires 2 factor auth is the risk low?
…