PkgRadar

Cargo · crates.io

fallow-cli

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 2.98.0

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · fallow-cli-2.98.0/src/flags.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · fallow-cli-2.98.0/src/init.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · fallow-cli-2.98.0/src/migrate/jsonc.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
2.98.0High risk362026-06-17
2.97.0High risk362026-06-16
2.96.0High risk362026-06-13
2.95.0High risk362026-06-12
2.94.0High risk362026-06-12
2.93.0High risk362026-06-11
2.92.1High risk362026-06-10
2.91.0High risk362026-06-09
2.90.0High risk362026-06-09
2.89.0High risk362026-06-05
2.88.3High risk362026-06-04
2.88.2High risk362026-06-03
2.88.1High risk362026-06-03
2.88.0High risk362026-06-03
2.87.0High risk362026-06-03
2.86.0High risk362026-06-02
2.85.0Review362026-05-30
2.84.0Review412026-05-28
2.83.0Review412026-05-27

Block this in CI

PkgRadar gates fallow-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]