PkgRadar

Cargo · crates.io

cfgd

Remote Payload: matched "curl\n "

Why PkgRadar flagged 0.4.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl\n " · cfgd-0.4.0/src/cli/module/tests.rs
mediumRemote Payloadmatched "curl " · cfgd-0.4.0/src/cli/plugin/mod.rs
mediumRemote Payloadmatched "curl " · cfgd-0.4.0/src/cli/tests.rs
mediumRemote Payloadmatched "curl " · cfgd-0.4.0/src/generate/scan/tests.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · cfgd-0.4.0/src/packages/brew/mod.rs
mediumRemote Payloadmatched "curl " · cfgd-0.4.0/src/packages/cargo.rs
mediumRemote Payloadmatched "curl " · cfgd-0.4.0/src/packages/nix.rs
mediumRemote Payloadmatched "curl " · cfgd-0.4.0/src/packages/npm.rs
mediumRemote Payloadmatched "curl " · cfgd-0.4.0/src/packages/parsers.rs
mediumRemote Payloadmatched "curl " · cfgd-0.4.0/src/packages/pipx.rs
mediumRemote Payloadmatched "curl " · cfgd-0.4.0/src/packages/simple/tests.rs
mediumRemote Payloadmatched "curl " · cfgd-0.4.0/src/packages/versions/tests.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.0Review1312026-05-30

Block this in CI

PkgRadar gates cfgd (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]