PkgRadar

PyPI · pypi.org

truss

Credential file access: matched "aws_access_key"

Why PkgRadar flagged 0.18.13

SeveritySignalEvidence
mediumCredential file accessmatched "aws_access_key" · truss-0.18.13/truss/contexts/image_builder/cache_warmer.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.18.13Review162026-06-17
0.18.12Review162026-06-16
0.18.11Review162026-06-16
0.18.10Review162026-06-15
0.18.9Review162026-06-11
0.18.8Review162026-06-10
0.18.7Review162026-06-09
0.18.6Review162026-06-05
0.18.5Review162026-06-04
0.18.5rc0Review162026-06-03
0.18.4Review162026-06-02
0.18.4rc0Review162026-05-30
0.18.3rc500Review162026-05-29

Block this in CI

PkgRadar gates truss (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi truss==0.18.13