PkgRadar

PyPI · pypi.org

holmesgpt

Py Import Time Network Call: Network call (urllib/requests/httpx/http.client) at install or import time.

Why PkgRadar flagged 0.32.0a0

SeveritySignalEvidence
highPy Import Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · holmesgpt-0.32.0a0/holmes/plugins/sources/github/__init__.py
highPy Import Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · holmesgpt-0.32.0a0/holmes/plugins/sources/jira/__init__.py
highPy Import Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · holmesgpt-0.32.0a0/holmes/plugins/sources/opsgenie/__init__.py
highPy Import Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · holmesgpt-0.32.0a0/holmes/plugins/sources/pagerduty/__init__.py
mediumCredential file accessmatched "aws_access_key" · holmesgpt-0.32.0a0/holmes/core/llm.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.32.0a0High risk452026-06-10
0.31.1High risk452026-05-30
0.31.0High risk452026-05-30

Block this in CI

PkgRadar gates holmesgpt (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi holmesgpt==0.32.0a0
holmesgpt — PyPI security scan | PkgRadar