PkgRadar

Cargo · crates.io

cadrum

Rs Build Time Command: Process spawn (std::process::Command) at build time.

Why PkgRadar flagged 0.8.11

SeveritySignalEvidence
mediumRs Build Time CommandProcess spawn (std::process::Command) at build time. · cadrum-0.8.11/build.rs
mediumRemote Payloadmatched "github.com/lzpel/cadrum/releases/download" · cadrum-0.8.11/build.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.8.11Review422026-06-15
0.8.10Review422026-06-13
0.8.5Review422026-06-03
0.8.4Review422026-06-03
0.8.3Review422026-05-29
0.8.2Review422026-05-29

Block this in CI

PkgRadar gates cadrum (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]