PkgRadar

Cargo · crates.io

calimero-server

Rs Build Time Network: HTTP / TCP network call inside build.rs — downloads at compile time.

Why PkgRadar flagged 0.11.0-rc.3

SeveritySignalEvidence
highRs Build Time NetworkHTTP / TCP network call inside build.rs — downloads at compile time. · calimero-server-0.11.0-rc.3/build.rs
mediumRemote Payloadmatched "github.com/{repo}/releases/download" · calimero-server-0.11.0-rc.3/build.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.11.0-rc.3High risk432026-06-11
0.11.0-rc.2High risk432026-06-08
0.11.0-rc.1High risk432026-06-02
0.10.1-rc.47High risk432026-05-30
0.10.1-rc.46High risk432026-05-30

Block this in CI

PkgRadar gates calimero-server (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]