PkgRadar

Cargo · crates.io

codewhale-tui

Rs Build Time Command: Process spawn (std::process::Command) at build time.

Why PkgRadar flagged 0.8.59

SeveritySignalEvidence
mediumRs Build Time CommandProcess spawn (std::process::Command) at build time. · codewhale-tui-0.8.59/build.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · codewhale-tui-0.8.59/src/config.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · codewhale-tui-0.8.59/src/network_policy.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · codewhale-tui-0.8.59/src/skills/install.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · codewhale-tui-0.8.59/src/tools/fetch_url.rs
mediumRemote Payloadmatched "curl " · codewhale-tui-0.8.59/src/tools/shell/tests.rs
mediumRemote Payloadmatched "curl " · codewhale-tui-0.8.59/src/tui/approval.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · codewhale-tui-0.8.59/src/tui/markdown_render.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.8.59High risk1192026-06-13
0.8.58High risk1192026-06-11
0.8.57High risk1192026-06-10
0.8.56High risk1192026-06-10
0.8.54High risk1192026-06-08
0.8.53High risk1192026-06-04
0.8.52High risk1192026-06-03
0.8.50High risk1192026-06-02
0.8.49High risk1192026-06-01
0.8.48High risk1192026-06-01

Block this in CI

PkgRadar gates codewhale-tui (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]