PkgRadar

Cargo · crates.io

colgrep

Remote Payload: matched "Invoke-WebRequest"

Why PkgRadar flagged 1.5.5

SeveritySignalEvidence
mediumRemote Payloadmatched "Invoke-WebRequest" · colgrep-1.5.5/src/commands/update.rs
mediumRemote Payloadmatched "github.com/microsoft/onnxruntime/releases/download" · colgrep-1.5.5/src/onnx_runtime.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
1.5.5Review242026-06-16
1.5.4Review242026-06-09
1.5.3Review242026-06-08
1.5.2Review242026-06-03
1.5.1Review242026-06-01
1.5.0Review242026-05-29

Block this in CI

PkgRadar gates colgrep (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]