PkgRadar

Cargo · crates.io

bctx-weave

Remote Payload: matched "curl "

Why PkgRadar flagged 0.1.28

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · bctx-weave-0.1.28/src/domains/lint/syft.rs
mediumRemote Payloadmatched "curl " · bctx-weave-0.1.28/src/domains/lint/trivy.rs
mediumRemote Payloadmatched "curl " · bctx-weave-0.1.28/src/domains/pkg/apt.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.28High risk412026-06-08
0.1.27High risk412026-06-08
0.1.26High risk412026-06-07

Block this in CI

PkgRadar gates bctx-weave (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]