PkgRadar

Cargo · crates.io

hjkl-anvil

Remote Payload: matched "github.com/mason-org/mason-registry/releases/download"

Why PkgRadar flagged 0.32.0

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/mason-org/mason-registry/releases/download" · hjkl-anvil-0.32.0/src/bin/sync_anvil.rs
mediumRemote Payloadmatched "github.com/{}/releases/download" · hjkl-anvil-0.32.0/src/installer.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.32.0Review242026-06-11
0.30.0Review242026-06-03
0.29.0Review242026-06-02
0.28.1Review242026-05-30

Block this in CI

PkgRadar gates hjkl-anvil (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]