PkgRadar

Cargo · crates.io

dofigen

Remote Payload: matched "curl "

Why PkgRadar flagged 2.9.0-beta.1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · dofigen-2.9.0-beta.1/src/dockerfile_struct.rs
mediumRemote Payloadmatched "curl " · dofigen-2.9.0-beta.1/src/frontend/spec.rs
mediumRemote Payloadmatched "curl " · dofigen-2.9.0-beta.1/src/parse/mod.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
2.9.0-beta.1High risk182026-06-03

Block this in CI

PkgRadar gates dofigen (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]