PkgRadar

Cargo · crates.io

bv-builder

Rs Build Time Network: HTTP / TCP network call inside build.rs — downloads at compile time.

Why PkgRadar flagged 0.1.40

SeveritySignalEvidence
highRs Build Time NetworkHTTP / TCP network call inside build.rs — downloads at compile time. · bv-builder-0.1.40/src/build.rs
highRs Build Time Env Token ReadReads CI/CD secret env vars (AWS / GitHub / GitLab / Cargo / NPM tokens) at build time. · bv-builder-0.1.40/src/build.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.40High risk1002026-06-07
0.1.39High risk1002026-06-07
0.1.38High risk1002026-05-30
0.1.37High risk1002026-05-30

Related campaigns

Block this in CI

PkgRadar gates bv-builder (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]