PyPI · pypi.org
z4j
Credential file access: matched ".azure\\"
Why PkgRadar flagged 1.6.8
| Severity | Signal | Evidence |
|---|---|---|
| high | Credential file access | matched ".azure\\" · z4j-1.6.8/backend/src/z4j_brain/observability/sentry.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.6.8 | High risk | 45 | 2026-06-08 |
1.6.7 | High risk | 45 | 2026-06-08 |
1.6.6 | High risk | 45 | 2026-06-07 |
1.6.5 | High risk | 45 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem pypi z4j==1.6.8