PkgRadar

Cargo · crates.io

forest-filecoin

Remote Payload: matched "github.com/filecoin-project/builtin-actors/releases/download"

Why PkgRadar flagged 0.33.6

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/filecoin-project/builtin-actors/releases/download" · forest-filecoin-0.33.6/src/networks/actors_bundle.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.33.6Review62026-06-05
0.33.5Review62026-06-03

Block this in CI

PkgRadar gates forest-filecoin (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]