PkgRadar

Cargo · crates.io

halfin

Rs Build Time Command Combo: Process spawn (std::process::Command) paired with network / base64 / env-token read at build time.

Why PkgRadar flagged 0.3.8

SeveritySignalEvidence
highRs Build Time Command ComboProcess spawn (std::process::Command) paired with network / base64 / env-token read at build time. · halfin-0.3.8/build.rs
highRs Build Time Env Token ReadReads CI/CD secret env vars (AWS / GitHub / GitLab / Cargo / NPM tokens) at build time. · halfin-0.3.8/build.rs
mediumRemote Payloadmatched "github.com/utreexo/utreexod/releases/download" · halfin-0.3.8/build.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.0Review352026-06-16
0.3.8High risk1122026-06-02
0.3.7High risk1122026-05-30

Related campaigns

Block this in CI

PkgRadar gates halfin (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]