PkgRadar

PyPI · pypi.org

docwright

Credential file access: matched "GITHUB_TOKEN"

Why PkgRadar flagged 0.1.43

SeveritySignalEvidence
mediumCredential file accessmatched "GITHUB_TOKEN" · docwright-0.1.43/docwright/outputs/pull_request.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.50Low risk02026-05-29
0.1.49Low risk02026-05-29
0.1.48Low risk02026-05-29
0.1.47Low risk02026-05-29
0.1.46Low risk02026-05-29
0.1.44Low risk02026-05-29
0.1.45Low risk02026-05-29
0.1.43Review102026-05-28
0.1.42Review102026-05-28
0.1.41Review102026-05-28
0.1.40Review102026-05-28
0.1.39Review102026-05-28
0.1.38Review102026-05-28
0.1.37Review102026-05-28
0.1.36Review102026-05-28
0.1.35Review102026-05-28
0.1.34Review102026-05-28
0.1.33Review102026-05-28
0.1.32Review102026-05-28
0.1.31Review102026-05-28
0.1.30Review102026-05-28
0.1.29Review102026-05-28
0.1.28Review102026-05-28

Block this in CI

PkgRadar gates docwright (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi docwright==0.1.43