Spectra Assure
Community
Docs
warningRisk: Secrets
Scanned: 9 days ago

google-cloud-dataproc

Artifact:
Google Cloud Dataproc API client library
License: Permissive (Apache-2.0)
Published: 4 months ago




SAFE Assessment

Compliance

Licenses
No license compliance issues
Secrets
16 web service credentials found

Security

Vulnerabilities
No known vulnerabilities detected
Hardening
No application hardening issues

Threats

Tampering
No evidence of software tampering
Malware
No evidence of malware inclusion

Popularity

471.16M
Total Downloads
Contributor
Declared Dependencies
28
Dependents

Top issues

Problem

Various network communication protocols allow including plaintext authentication credentials. Information such as user names and passwords could be passed through a non-encrypted channel, and therefore intercepted by malicious actors. Credentials are considered secrets, and should be kept encrypted until they are used. This policy control matches the following URI pattern protocol://username:password@domain within any software package component.

Prevalence in PyPI community

21 packages
found in
Top 100
85 packages
found in
Top 1k
369 packages
found in
Top 10k
6869 packages
in community

Next steps

Review the reported matches. If the warning refers to a placeholder credential value, it can be safely ignored.

Top behaviors

Prevalence in PyPI community

Behavior often found in this community (Common)
75 packages
found in
Top 100
451 packages
found in
Top 1k
3488 packages
found in
Top 10k
109392 packages
in community

Prevalence in PyPI community

Behavior often found in this community (Common)
26 packages
found in
Top 100
114 packages
found in
Top 1k
539 packages
found in
Top 10k
12386 packages
in community

Prevalence in PyPI community

Behavior often found in this community (Common)
68 packages
found in
Top 100
540 packages
found in
Top 1k
3644 packages
found in
Top 10k
154572 packages
in community

Prevalence in PyPI community

Behavior often found in this community (Common)
49 packages
found in
Top 100
364 packages
found in
Top 1k
2374 packages
found in
Top 10k
87567 packages
in community

Prevalence in PyPI community

Behavior often found in this community (Common)
19 packages
found in
Top 100
165 packages
found in
Top 1k
829 packages
found in
Top 10k
18425 packages
in community

Top vulnerabilities

No vulnerabilities found.

This website uses cookies to ensure the best website experience. By continuing to use this website you are giving your consent to cookies being used. Detailed information about our use of cookies is here.