PkgRadar

PyPI · pypi.org

ontoforge

Credential file access: matched "AWS_ACCESS_KEY"

Why PkgRadar flagged 3.8.0

SeveritySignalEvidence
mediumCredential file accessmatched "AWS_ACCESS_KEY" · ontoforge-3.8.0/src/graph_publisher.py

Scanned versions

VersionVerdictScoreScanned (UTC)
3.8.0Review132026-06-08

Block this in CI

PkgRadar gates ontoforge (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi ontoforge==3.8.0