PkgRadar

PyPI · pypi.org

querysource

Credential file access: matched "GOOGLE_APPLICATION_CREDENTIALS"

Why PkgRadar flagged 4.4.0

SeveritySignalEvidence
mediumCredential file accessmatched "GOOGLE_APPLICATION_CREDENTIALS" · querysource-4.4.0/querysource/providers/sources/ga.py

Scanned versions

VersionVerdictScoreScanned (UTC)
4.4.0Review92026-05-30

Block this in CI

PkgRadar gates querysource (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi querysource==4.4.0