PkgRadar

Cargo · crates.io

is-it-slop

Rs Build Time Network: HTTP / TCP network call inside build.rs — downloads at compile time.

Why PkgRadar flagged 0.6.3

SeveritySignalEvidence
highRs Build Time NetworkHTTP / TCP network call inside build.rs — downloads at compile time. · is-it-slop-0.6.3/build.rs
mediumRemote Payloadmatched "curl " · is-it-slop-0.6.3/build.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · is-it-slop-0.6.3/src/cli/self_update.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.6.3High risk512026-06-02
0.6.2High risk512026-06-02
0.6.1High risk512026-06-02
0.6.0High risk742026-06-01
0.6.0-beta.1High risk742026-06-01
0.6.0-beta.0High risk742026-06-01
0.6.0-alpha.5High risk742026-06-01

Block this in CI

PkgRadar gates is-it-slop (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]