PkgRadar

PyPI · pypi.org

awscli

Credential file access: matched "aws_access_key"

Why PkgRadar flagged 1.45.22

SeveritySignalEvidence
mediumCredential file accessmatched "aws_access_key" · awscli-1.45.22/awscli/customizations/codedeploy/register.py
mediumCredential file accessmatched "AWS_ACCESS_KEY" · awscli-1.45.22/awscli/customizations/codedeploy/systems.py
mediumCredential file accessmatched ".aws/" · awscli-1.45.22/awscli/customizations/history/commands.py
mediumCredential file accessmatched "AWS_ACCESS_KEY" · awscli-1.45.22/awscli/testutils.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.45.22Review222026-06-03
1.45.21Review222026-06-03
1.45.20Review222026-06-02
1.45.19Review222026-06-01
1.45.18Review222026-05-29
1.45.17Review252026-05-28
1.45.16Review302026-05-27
1.45.15Review582026-05-26

Block this in CI

PkgRadar gates awscli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi awscli==1.45.22