PkgRadar

Cargo · crates.io

agave-install

Remote Payload: matched "github.com/anza-xyz/agave/releases/download"

Why PkgRadar flagged 4.1.0-rc.0

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/anza-xyz/agave/releases/download" · agave-install-4.1.0-rc.0/src/command.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
4.1.0-rc.0Review62026-06-12
4.1.0-beta.3Review62026-06-05
4.1.0-beta.2Review62026-06-01

Block this in CI

PkgRadar gates agave-install (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]
agave-install — Cargo security scan | PkgRadar