PkgRadar

Cargo · crates.io

ins

Remote Payload: matched "curl "

Why PkgRadar flagged 0.13.35

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · ins-0.13.35/src/common/network.rs
mediumRemote Payloadmatched "curl " · ins-0.13.35/src/dev/setup.rs
mediumRemote Payloadmatched "github.com/ryanoasis/nerd-fonts/releases/download" · ins-0.13.35/src/doctor/checks/nerdfont.rs
mediumRemote Payloadmatched "curl " · ins-0.13.35/src/doctor/checks/tools.rs
mediumRemote Payloadmatched "github.com/stenzek/duckstation/releases/download" · ins-0.13.35/src/game/platforms/duckstation.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · ins-0.13.35/src/game/platforms/ludusavi/manifest.rs
mediumRemote Payloadmatched "curl " · ins-0.13.35/src/video/document/mod.rs
mediumRemote Payloadmatched "curl " · ins-0.13.35/src/video/pipeline/setup.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · ins-0.13.35/src/wallpaper/common.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.13.35High risk752026-05-30

Block this in CI

PkgRadar gates ins (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]