PyPI · pypi.org
finops-mcp
Credential file access: matched "AWS_SECRET_ACCESS_KEY"
Why PkgRadar flagged 0.8.64
| Severity | Signal | Evidence |
|---|---|---|
| medium | Credential file access | matched "AWS_SECRET_ACCESS_KEY" · finops_mcp-0.8.64/src/finops/doctor.py |
| medium | Credential file access | matched "AWS_ACCESS_KEY" · finops_mcp-0.8.64/src/finops/server.py |
| medium | Credential file access | matched "GOOGLE_APPLICATION_CREDENTIALS" · finops_mcp-0.8.64/src/finops/connectors/gcp.py |
| medium | Credential file access | matched "GOOGLE_APPLICATION_CREDENTIALS" · finops_mcp-0.8.64/src/finops/security/oauth/gcp.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.8.64 | Review | 100 | 2026-06-13 |
0.8.63 | Review | 100 | 2026-06-13 |
0.8.62 | Review | 100 | 2026-06-13 |
0.8.61 | Review | 100 | 2026-06-12 |
0.8.60 | Review | 100 | 2026-06-10 |
0.8.59 | Review | 100 | 2026-06-10 |
0.8.58 | Review | 100 | 2026-06-10 |
0.8.57 | Review | 100 | 2026-06-10 |
0.8.56 | Review | 100 | 2026-06-09 |
0.8.55 | Review | 100 | 2026-06-08 |
0.8.54 | Review | 100 | 2026-06-08 |
0.8.53 | Review | 100 | 2026-06-07 |
0.8.52 | Review | 100 | 2026-06-06 |
0.8.51 | Review | 100 | 2026-06-06 |
0.8.50 | Review | 100 | 2026-06-06 |
0.8.49 | Review | 100 | 2026-06-06 |
0.8.48 | Review | 100 | 2026-06-06 |
0.8.47 | Review | 100 | 2026-06-06 |
0.8.46 | Review | 100 | 2026-06-04 |
0.8.45 | Review | 100 | 2026-06-04 |
0.8.44 | Review | 100 | 2026-06-04 |
0.8.43 | Review | 100 | 2026-06-04 |
0.8.42 | Review | 100 | 2026-06-03 |
0.8.41 | Review | 100 | 2026-06-03 |
0.8.40 | Review | 100 | 2026-06-03 |
0.8.39 | Review | 100 | 2026-06-03 |
0.8.38 | Review | 100 | 2026-06-02 |
0.8.37 | Review | 100 | 2026-06-02 |
Block this in CI
pkgradar gate --ecosystem pypi finops-mcp==0.8.64