PkgRadar

PyPI · pypi.org

athanor-sdk

Credential file access: matched "AWS_ACCESS_KEY"

Why PkgRadar flagged 0.8.20

SeveritySignalEvidence
mediumCredential file accessmatched "AWS_ACCESS_KEY" · kairos/auto_setup.py
mediumCredential file accessmatched "AWS_ACCESS_KEY" · kairos/doctor.py
mediumCredential file accessmatched "AWS_ACCESS_KEY" · kairos/llm_config.py
mediumCredential file accessmatched "AWS_ACCESS_KEY" · kairos/quickstart.py
mediumCredential file accessmatched "AWS_ACCESS_KEY" · kairos/setup_wizard.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.8.20Review552026-06-15
0.8.19Review552026-06-15
0.8.18Review552026-06-15
0.8.17Review552026-06-14
0.8.15Review552026-06-11
0.8.14Review552026-06-11
0.8.13Review552026-06-10
0.8.12Review552026-06-09
0.8.11Review552026-06-08
0.8.10Review552026-06-06
0.8.9Review552026-06-06
0.8.8Review552026-06-05
0.8.7Review552026-06-05
0.8.6Review552026-06-02
0.8.5Review552026-06-02
0.8.3Review552026-05-30
0.8.1Review552026-05-30
0.8.2Review552026-05-30

Block this in CI

PkgRadar gates athanor-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi athanor-sdk==0.8.20