PkgRadar

PyPI · pypi.org

mergify-cli

Credential file access: matched "GITHUB_TOKEN"

Why PkgRadar flagged 2026.5.29.1

SeveritySignalEvidence
mediumCredential file accessmatched "GITHUB_TOKEN" · mergify_cli-2026.5.29.1/mergify_cli/stack/cli.py
mediumCredential file accessmatched "GITHUB_TOKEN" · mergify_cli-2026.5.29.1/mergify_cli/utils.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.16.1Low risk02026-06-16
2026.6.15.1Low risk02026-06-15
2026.6.11.3Low risk02026-06-11
2026.6.11.2Low risk02026-06-11
2026.6.8.1Low risk02026-06-08
2026.6.5.1Low risk02026-06-05
2026.6.4.1Low risk02026-06-04
2026.6.3.1Low risk02026-06-03
2026.6.2.4Low risk02026-06-02
2026.6.2.3Low risk02026-06-02
2026.6.2.2Low risk02026-06-02
2026.6.2.1Low risk02026-06-02
2026.5.29.2Low risk02026-05-29
2026.5.29.1Review122026-05-29
2026.5.27.1Review152026-05-27

Block this in CI

PkgRadar gates mergify-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi mergify-cli==2026.5.29.1