PkgRadar

PyPI · pypi.org

fromager

Credential file access: matched "GITHUB_TOKEN"

Why PkgRadar flagged 0.86.0

SeveritySignalEvidence
mediumCredential file accessmatched "GITHUB_TOKEN" · fromager-0.86.0/src/fromager/request_session.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.88.0Low risk02026-06-15
0.87.0Low risk02026-06-01
0.86.0Review72026-05-29

Block this in CI

PkgRadar gates fromager (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi fromager==0.86.0
fromager — PyPI security scan | PkgRadar