PkgRadar

Cargo · crates.io

cherub

Remote Payload: matched "curl "

Why PkgRadar flagged 0.2.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · cherub-0.2.0/src/enforcement/mod.rs
mediumRemote Payloadmatched "curl " · cherub-0.2.0/src/enforcement/policy.rs
mediumRemote Payloadmatched "curl " · cherub-0.2.0/src/tools/dev_environment.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.0High risk462026-06-02
0.1.1High risk462026-05-31

Block this in CI

PkgRadar gates cherub (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]