PkgRadar

Cargo · crates.io

cargo-bundle

Remote Payload: matched "github.com/AppImage/type2-runtime/releases/download"

Why PkgRadar flagged 0.11.0

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/AppImage/type2-runtime/releases/download" · cargo-bundle-0.11.0/src/bundle/linux/appimage_bundle.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.11.0Review82026-05-30

Block this in CI

PkgRadar gates cargo-bundle (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]