PkgRadar

PyPI · pypi.org

openhands-ai

Credential file access: matched "AWS_ACCESS_KEY"

Why PkgRadar flagged 1.8.0

SeveritySignalEvidence
mediumCredential file accessmatched "AWS_ACCESS_KEY" · openhands_ai-1.8.0/openhands/app_server/file_store/s3.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.8.0Review152026-06-10

Block this in CI

PkgRadar gates openhands-ai (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi openhands-ai==1.8.0