PkgRadar

PyPI · pypi.org

ontomesh

Credential file access: matched "AWS_ACCESS_KEY"

Why PkgRadar flagged 3.7.1.dev0

SeveritySignalEvidence
mediumCredential file accessmatched "AWS_ACCESS_KEY" · ontomesh-3.7.1.dev0/src/graph_publisher.py

Scanned versions

VersionVerdictScoreScanned (UTC)
3.7.1.dev0Review132026-06-05

Block this in CI

PkgRadar gates ontomesh (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi ontomesh==3.7.1.dev0