PkgRadar

Cargo · crates.io

axbuild

Rs Build Time Command: Process spawn (std::process::Command) at build time.

Why PkgRadar flagged 0.4.9

SeveritySignalEvidence
mediumRs Build Time CommandProcess spawn (std::process::Command) at build time. · axbuild-0.4.9/src/test/build.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · axbuild-0.4.9/src/axvisor/image/config.rs
mediumRemote Payloadmatched "github.com/rcore-os/tgosimages/releases/download" · axbuild-0.4.9/src/rootfs/store.rs
mediumRemote Payloadmatched "curl " · axbuild-0.4.9/src/starry/test.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.11Review742026-06-11
0.4.10Review742026-06-10
0.4.9High risk662026-06-03

Block this in CI

PkgRadar gates axbuild (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]