PkgRadar

PyPI · pypi.org

forge-hermes-plugin

Credential file access: matched "GITHUB_TOKEN"

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.8Low risk02026-06-09
0.3.7Low risk02026-06-09
0.3.6Low risk02026-06-09
0.2.117Low risk02026-06-07
0.2.116Low risk02026-06-07
0.2.115Low risk02026-06-07
0.2.114Low risk02026-06-07
0.2.113Low risk02026-06-07
0.2.109Low risk02026-06-06
0.2.108Low risk02026-06-06
0.2.107Low risk02026-06-06
0.2.106Low risk02026-06-04
0.2.105Low risk02026-06-04
0.2.104Low risk02026-06-04
0.2.102Low risk02026-06-04
0.2.101Low risk02026-06-02
0.2.100Low risk02026-06-02
0.2.96Low risk02026-05-31
0.2.95Review52026-05-28
0.2.93Review52026-05-28

Block this in CI

PkgRadar gates forge-hermes-plugin (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi forge-hermes-plugin==0.2.95