PkgRadar

PyPI · pypi.org

openmetadata-ingestion

Credential file access: matched "AWS_ACCESS_KEY"

Why PkgRadar flagged 1.12.11.0

SeveritySignalEvidence
mediumCredential file accessmatched "AWS_ACCESS_KEY" · openmetadata_ingestion-1.12.11.0/src/metadata/readers/dataframe/parquet.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.12.11.0Review222026-06-12
1.12.10.1Review222026-06-08
1.13.0.0Review152026-06-08
1.12.10.0Review222026-06-03
1.12.9.0Review222026-05-30
1.12.8.10Review272026-05-29

Block this in CI

PkgRadar gates openmetadata-ingestion (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi openmetadata-ingestion==1.12.11.0