PkgRadar

PyPI · pypi.org

openrag

Credential file access: matched "aws_access_key"

Why PkgRadar flagged 0.5.0

SeveritySignalEvidence
highCredential file accessmatched "aws_access_key" · openrag-0.5.0/src/tui/managers/env_manager.py
mediumRemote Payloadmatched "curl " · openrag-0.5.0/src/tui/utils/startup_checks.py
mediumCredential file accessmatched "aws_secret_access_key" · openrag-0.5.0/src/connectors/connection_manager.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.0High risk592026-05-30
0.5.0.dev38High risk592026-05-30
0.5.0.dev37High risk592026-05-30
0.5.0.dev36High risk592026-05-30
0.5.0.dev35High risk592026-05-30
0.5.0.dev34High risk592026-05-30

Block this in CI

PkgRadar gates openrag (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi openrag==0.5.0