PyPI · pypi.org
flexible-graphrag
Credential file access: matched "GOOGLE_APPLICATION_CREDENTIALS"
Why PkgRadar flagged 0.6.2
| Severity | Signal | Evidence |
|---|---|---|
| medium | Credential file access | matched "GOOGLE_APPLICATION_CREDENTIALS" · flexible_graphrag-0.6.2/langchain/graph/pg_store_adapters/spanner_adapter.py |
| medium | Credential file access | matched "GOOGLE_APPLICATION_CREDENTIALS" · flexible_graphrag-0.6.2/langchain/llm/embedding_factory.py |
| medium | Credential file access | matched "AWS_ACCESS_KEY" · flexible_graphrag-0.6.2/llamaindex/graph/adapters/neptune_analytics_adapter.py |
| medium | Credential file access | matched "GOOGLE_APPLICATION_CREDENTIALS" · flexible_graphrag-0.6.2/llamaindex/llm/embedding_factory.py |
| medium | Credential file access | matched "GOOGLE_APPLICATION_CREDENTIALS" · flexible_graphrag-0.6.2/llamaindex/llm/llm_factory.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.6.2 | Review | 90 | 2026-06-02 |
Block this in CI
pkgradar gate --ecosystem pypi flexible-graphrag==0.6.2