PyPI · pypi.org
oneport-secretscan
Py Runtime Dynamic Dangerous Import: Dynamic __import__('os') — reflection bypass for static checks.
Why PkgRadar flagged 0.5.1
| Severity | Signal | Evidence |
|---|---|---|
| high | Py Runtime Dynamic Dangerous Import | Dynamic __import__('os') — reflection bypass for static checks. · oneport_secretscan-0.5.1/secretscan/cli.py |
| medium | Credential file access | matched "aws_access_key" · oneport_secretscan-0.5.1/secretscan/active_verifier.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.5.1 | High risk | 45 | 2026-06-09 |
0.5.0 | High risk | 45 | 2026-06-09 |
Block this in CI
pkgradar gate --ecosystem pypi oneport-secretscan==0.5.1