PkgRadar

Cargo · crates.io

mero-auth

Rs Build Time Network: HTTP / TCP network call inside build.rs — downloads at compile time.

Why PkgRadar flagged 0.11.0-rc.4

SeveritySignalEvidence
highRs Build Time NetworkHTTP / TCP network call inside build.rs — downloads at compile time. · mero-auth-0.11.0-rc.4/build.rs
mediumRemote Payloadmatched "github.com/{repo}/releases/download" · mero-auth-0.11.0-rc.4/build.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.11.0-rc.4High risk432026-06-17
0.11.0-rc.3High risk432026-06-11
0.11.0-rc.2High risk432026-06-08
0.10.1-rc.46High risk432026-05-30

Block this in CI

PkgRadar gates mero-auth (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]