PkgRadar

PyPI · pypi.org

taf

Credential file access: matched ".ssh/"

Why PkgRadar flagged 0.38.4

SeveritySignalEvidence
mediumCredential file accessmatched ".ssh/" · taf-0.38.4/taf/git.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.38.4Review32026-06-09
0.38.3Review32026-05-27

Block this in CI

PkgRadar gates taf (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi taf==0.38.4