PkgRadar

PyPI · pypi.org

marin-core

Credential file access: matched "GOOGLE_APPLICATION_CREDENTIALS"

Why PkgRadar flagged 0.2.14.dev202606120949

SeveritySignalEvidence
mediumCredential file accessmatched "GOOGLE_APPLICATION_CREDENTIALS" · marin_core-0.2.14.dev202606120949/marin/utilities/upload_gcs_to_hf.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.14.dev202606120949Review152026-06-12
0.2.13.dev202606110957Review152026-06-11
0.2.12.dev202606100934Review152026-06-10
0.2.11.dev202606081009Review152026-06-08
0.2.10.dev202606070840Review152026-06-07
0.2.9.dev202606060818Review152026-06-06
0.2.8.dev202606050858Review152026-06-05
0.2.7.dev202606040937Review152026-06-04
0.2.6.dev202606031026Review152026-06-03
0.2.5.dev202606020954Review152026-06-02
0.2.4.dev202606011101Review152026-06-01
0.2.3.dev202605310830Review152026-05-31
0.2.2.dev202605300811Review152026-05-30
0.2.1.dev202605292307Review152026-05-29

Block this in CI

PkgRadar gates marin-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi marin-core==0.2.14.dev202606120949