PkgRadar

PyPI · pypi.org

amplify-media-migrator

Credential file access: matched "GOOGLE_APPLICATION_CREDENTIALS"

Why PkgRadar flagged 1.4.0

SeveritySignalEvidence
mediumCredential file accessmatched "GOOGLE_APPLICATION_CREDENTIALS" · amplify_media_migrator-1.4.0/amplify_media_migrator/config.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.4.0Review152026-06-09
1.3.0Review152026-06-07
1.2.18Review152026-06-07
1.2.17Review152026-06-07
1.2.14Review152026-06-05
1.2.15Review152026-06-05
1.2.16Review152026-06-05
1.2.13Review152026-06-02
1.2.12Review152026-06-01
1.2.11Review152026-05-31
1.2.10Review152026-05-31
1.2.9Review152026-05-31
1.2.8Review152026-05-29
1.2.7Review152026-05-29
1.2.6Review152026-05-28

Block this in CI

PkgRadar gates amplify-media-migrator (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi amplify-media-migrator==1.4.0
amplify-media-migrator — PyPI security scan | PkgRadar