PkgRadar

Cargo · crates.io

mujoco-rs

Rs Build Time Network: HTTP / TCP network call inside build.rs — downloads at compile time.

Why PkgRadar flagged 5.0.0+mj-3.9.0

SeveritySignalEvidence
highRs Build Time NetworkHTTP / TCP network call inside build.rs — downloads at compile time. · mujoco-rs-5.0.0+mj-3.9.0/build.rs
mediumRemote Payloadmatched "github.com/google-deepmind/mujoco/releases/download" · mujoco-rs-5.0.0+mj-3.9.0/build.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
5.0.0+mj-3.9.0High risk432026-06-13

Block this in CI

PkgRadar gates mujoco-rs (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]+mj-3.9.0