PkgRadar

Cargo · crates.io

assay-cli

Remote Payload: matched "curl "

Why PkgRadar flagged 3.15.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · assay-cli-3.15.0/src/cli/commands/evidence/mapping.rs
mediumRemote Payloadmatched "curl " · assay-cli-3.15.0/src/cli/commands/init_ci.rs
mediumRemote Payloadmatched "curl\n " · assay-cli-3.15.0/src/templates.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
3.15.0High risk462026-06-03
3.14.0High risk462026-06-01
3.13.0High risk462026-06-01

Block this in CI

PkgRadar gates assay-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]