PyPI · pypi.org
openrag
Credential file access: matched "aws_access_key"
Why PkgRadar flagged 0.5.0
| Severity | Signal | Evidence |
|---|---|---|
| high | Credential file access | matched "aws_access_key" · openrag-0.5.0/src/tui/managers/env_manager.py |
| medium | Remote Payload | matched "curl " · openrag-0.5.0/src/tui/utils/startup_checks.py |
| medium | Credential file access | matched "aws_secret_access_key" · openrag-0.5.0/src/connectors/connection_manager.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.5.0 | High risk | 59 | 2026-05-30 |
0.5.0.dev38 | High risk | 59 | 2026-05-30 |
0.5.0.dev37 | High risk | 59 | 2026-05-30 |
0.5.0.dev36 | High risk | 59 | 2026-05-30 |
0.5.0.dev35 | High risk | 59 | 2026-05-30 |
0.5.0.dev34 | High risk | 59 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem pypi openrag==0.5.0