PkgRadar

PyPI · pypi.org

github-twin

Credential file access: matched "GITHUB_TOKEN"

Why PkgRadar flagged 0.0.16

SeveritySignalEvidence
mediumCredential file accessmatched "GITHUB_TOKEN" · github_twin-0.0.16/src/github_twin/cli.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.17Low risk02026-05-29
0.0.16Review182026-05-28

Block this in CI

PkgRadar gates github-twin (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi github-twin==0.0.16