PkgRadar

PyPI · pypi.org

pulumi-aws

Credential file access: matched ".aws"

Why PkgRadar flagged 7.32.0a1779871574

SeveritySignalEvidence
highCredential file accessmatched ".aws" · pulumi_aws-7.32.0a1779871574/pulumi_aws/amplify/webhook.py
highCredential file accessmatched ".aws" · pulumi_aws-7.32.0a1779871574/pulumi_aws/codebuild/webhook.py
highCredential file accessmatched ".aws" · pulumi_aws-7.32.0a1779871574/pulumi_aws/codepipeline/webhook.py
mediumRemote Payloadmatched "curl " · pulumi_aws-7.32.0a1779871574/pulumi_aws/kinesis/_inputs.py
mediumRemote Payloadmatched "curl " · pulumi_aws-7.32.0a1779871574/pulumi_aws/kinesis/outputs.py
mediumRemote Payloadmatched "curl " · pulumi_aws-7.32.0a1779871574/pulumi_aws/ssm/association.py

Scanned versions

VersionVerdictScoreScanned (UTC)
7.33.0a1781077846Low risk02026-06-10
7.33.0a1780990142Low risk02026-06-09
7.33.0a1780729991Low risk02026-06-06
7.33.0a1780645471Low risk02026-06-05
6.83.4Low risk02026-06-03
7.33.0a1780472821Low risk02026-06-03
7.33.0a1780317927Low risk02026-06-01
7.33.0a1780127692Low risk02026-05-30
7.32.0Low risk02026-05-29
7.32.0a1780075428Low risk02026-05-29
7.32.0a1780014499Low risk02026-05-29
7.32.0a1779953541Low risk02026-05-28
7.32.0a1779871574Review332026-05-27
7.31.0Review332026-05-26

Block this in CI

PkgRadar gates pulumi-aws (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi pulumi-aws==7.32.0a1779871574