PkgRadar

PyPI · pypi.org

servonaut

Credential file access: matched "GOOGLE_APPLICATION_CREDENTIALS"

Why PkgRadar flagged 2.19.7

SeveritySignalEvidence
mediumCredential file accessmatched "GOOGLE_APPLICATION_CREDENTIALS" · servonaut-2.19.7/src/servonaut/services/gcp_service.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.19.7Review752026-06-16
2.19.6Review752026-06-13
2.19.5Review752026-06-13
2.19.4Review752026-06-11
2.19.3Review752026-06-11
2.19.2Review752026-06-11
2.19.1Review752026-06-10
2.19.0Review752026-06-10
2.18.0Review752026-06-10
2.17.3Review752026-06-07
2.17.2Review752026-06-04
2.17.1Review702026-06-04
2.17.0Review702026-06-04
2.16.3Review702026-06-02
2.16.2Review702026-06-01
2.16.1Review702026-05-30
2.16.0Review702026-05-30

Block this in CI

PkgRadar gates servonaut (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi servonaut==2.19.7