PkgRadar

PyPI · pypi.org

kestrel-sovereign

Credential file access: matched "GOOGLE_APPLICATION_CREDENTIALS"

Why PkgRadar flagged 0.26.0

SeveritySignalEvidence
mediumCredential file accessmatched "GOOGLE_APPLICATION_CREDENTIALS" · kestrel_sovereign-0.26.0/kestrel_sovereign/kestrel_agent.py
mediumCredential file accessmatched "GOOGLE_APPLICATION_CREDENTIALS" · kestrel_sovereign-0.26.0/kestrel_sovereign/features/vertex_ai/vertex_ai_manager.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.26.0Review352026-06-13
0.25.0Review352026-06-11
0.24.0Review352026-06-10
0.23.0Review352026-06-08
0.22.0Review352026-06-03
0.21.2Review352026-06-01
0.21.1Review352026-06-01
0.21.0Review352026-06-01
0.20.0Review352026-05-31
0.15.2Review352026-05-30
0.15.1Review352026-05-30
0.15.0Review352026-05-30
0.19.0Review352026-05-30
0.18.0Review352026-05-29
0.17.0Review352026-05-29
0.16.0Review352026-05-29

Block this in CI

PkgRadar gates kestrel-sovereign (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi kestrel-sovereign==0.26.0