PkgRadar

PyPI · pypi.org

plumbum

Credential file access: matched ".ssh/"

Why PkgRadar flagged 2.0.0

SeveritySignalEvidence
mediumCredential file accessmatched ".ssh/" · plumbum-2.0.0/plumbum/machines/paramiko_machine.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.0Review52026-06-04

Block this in CI

PkgRadar gates plumbum (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi plumbum==2.0.0