PkgRadar

Package evidence

pulumi-aws==7.32.0a1779871574

Credential file access: matched ".aws"

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
623Mature · −50% score
First published
Jun 2018

Effective trust discount applied: 50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["pulumi-aws==7.32.0a1779871574"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["pulumi-aws==7.32.0a1779871574"],"fail_on":"review"}'
Publisherunknown
Artifact bytes9,601,420
Previous versionnone
Published2026-05-27T09:44:10
SHA-2567b052d2b131483aea61c6e394ec3efde507bc85c0cb34b117206e1e657cb951f

Why flagged

What the scanner saw

Credential file access: matched ".aws"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
33Score
7.32.0a1779871574Version
Status history (1 event)
  1. newavailable · risk review · score 33 · status changed

Evidence

Static findings

2321 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/amplify/webhook.pymatched ".aws"30
highCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/codebuild/webhook.pymatched ".aws"30
highCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/codepipeline/webhook.pymatched ".aws"30
mediumRemote Payloadpulumi_aws-7.32.0a1779871574/pulumi_aws/kinesis/_inputs.pymatched "curl "12
mediumRemote Payloadpulumi_aws-7.32.0a1779871574/pulumi_aws/kinesis/outputs.pymatched "curl "12
mediumRemote Payloadpulumi_aws-7.32.0a1779871574/pulumi_aws/ssm/association.pymatched "curl "12
Show all 2321 findings (low-signal and informational)

Showing 60 of 2321 findings.

SeverityKindPathDetailPoints
highCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/amplify/webhook.pymatched ".aws"30
highCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/codebuild/webhook.pymatched ".aws"30
highCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/codepipeline/webhook.pymatched ".aws"30
mediumRemote Payloadpulumi_aws-7.32.0a1779871574/pulumi_aws/kinesis/_inputs.pymatched "curl "12
mediumRemote Payloadpulumi_aws-7.32.0a1779871574/pulumi_aws/kinesis/outputs.pymatched "curl "12
mediumRemote Payloadpulumi_aws-7.32.0a1779871574/pulumi_aws/ssm/association.pymatched "curl "12
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/_inputs.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/accessanalyzer/_inputs.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/accessanalyzer/analyzer.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/accessanalyzer/archive_rule.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/accessanalyzer/outputs.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/acm/_inputs.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/acm/certificate.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/acm/certificate_validation.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/acm/get_certificate.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/acm/outputs.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/acmpca/_inputs.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/acmpca/certificate.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/acmpca/certificate_authority.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/acmpca/certificate_authority_certificate.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/acmpca/get_certificate.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/acmpca/get_certificate_authority.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/acmpca/outputs.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/acmpca/permission.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/acmpca/policy.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/alb/get_listener.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/alb/get_load_balancer.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/alb/get_target_group.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/alb/listener.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/alb/listener_certificate.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/alb/listener_rule.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/alb/load_balancer.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/alb/target_group.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/alb/target_group_attachment.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/amp/alert_manager_definition.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/amp/get_default_scraper_configuration.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/amp/get_workspace.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/amp/get_workspaces.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/amp/query_logging_configuration.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/amp/resource_policy.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/amp/rule_group_namespace.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/amp/scraper.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/amp/workspace.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/amp/workspace_configuration.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/amplify/app.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/amplify/backend_environment.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/amplify/branch.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/amplify/domain_association.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/apigateway/_inputs.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/apigateway/account.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/apigateway/api_key.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/apigateway/authorizer.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/apigateway/base_path_mapping.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/apigateway/client_certificate.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/apigateway/deployment.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/apigateway/documentation_part.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/apigateway/documentation_version.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/apigateway/domain_name.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/apigateway/domain_name_access_association.pymatched ".aws"5
lowCredential file accesspulumi_aws-7.32.0a1779871574/pulumi_aws/apigateway/get_api_keys.pymatched ".aws"5