Top issues
Problem
Private keys and certificates are considered sensitive information that should not be included in released software packages. However, developers frequently release sensitive information alongside their applications to facilitate automated software testing. Testing keys and certificates often proliferate through the software supply chain. When such information gets shared publicly, it is catalogued by file reputation databases. Any private key and certificate files seen by a file reputation database prior to configured time threshold can be automatically suppressed. Commonly shared sensitive information is not considered to be secret.Prevalence in PyPI community
37 packages
found in
Top 100
169 packages
found in
Top 1k
753 packages
found in
Top 10k
16.54k packages
in community
Next steps
Review the commonly shared sensitive information for evidence of inadvertently exposed secrets.
If the keys were published unintentionally and the software has been made public, you should revoke the keys and file a security incident.
Top behaviors
Opens a socket listening for an incoming connection.
network
Prevalence in PyPI community
Behavior often found in this community (Common)
10 packages
found in
Top 100
78 packages
found in
Top 1k
317 packages
found in
Top 10k
9.18k packages
in community
Contains URLs that link to interesting file formats.
network
Prevalence in PyPI community
Behavior often found in this community (Common)
76 packages
found in
Top 100
459 packages
found in
Top 1k
3531 packages
found in
Top 10k
105.97k packages
in community
Contains URLs related to file exchange services.
network
Prevalence in PyPI community
Behavior often found in this community (Common)
4 packages
found in
Top 100
54 packages
found in
Top 1k
250 packages
found in
Top 10k
4.26k packages
in community
Contains URLs related to cloud storage services.
network
Prevalence in PyPI community
Behavior often found in this community (Common)
19 packages
found in
Top 100
170 packages
found in
Top 1k
938 packages
found in
Top 10k
23.27k packages
in community
Queries the value of an environment variable.
search
Prevalence in PyPI community
Behavior often found in this community (Common)
73 packages
found in
Top 100
614 packages
found in
Top 1k
4460 packages
found in
Top 10k
173.79k packages
in community
Top vulnerabilities
No vulnerabilities found.