PkgRadar

Cargo · crates.io

mur-common

Remote Payload: matched "curl "

Why PkgRadar flagged 2.25.1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · mur-common-2.25.1/src/coordination/conformance.rs
mediumRemote Payloadmatched "curl " · mur-common-2.25.1/src/coordination/plan.rs
mediumRemote Payloadmatched "curl " · mur-common-2.25.1/src/skill/scan/executable.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
2.25.1High risk462026-06-16
2.25.0High risk462026-06-16
2.24.5High risk462026-06-15
2.24.4High risk462026-06-14
2.24.3High risk462026-06-14
2.24.2High risk462026-06-13
2.24.1High risk462026-06-12
2.24.0High risk462026-06-12
2.23.0High risk462026-06-11
2.22.20High risk462026-06-10
2.22.19High risk462026-06-10
2.22.18High risk462026-06-10
2.22.17High risk462026-06-09
2.22.16High risk462026-06-09
2.22.15High risk462026-06-07
2.22.14High risk462026-06-04
2.22.13High risk462026-06-03
2.22.12High risk462026-06-03
2.22.11High risk462026-06-03
2.22.10High risk462026-06-03
2.22.9High risk462026-06-03
2.22.8High risk462026-06-03
2.22.7High risk462026-06-02
2.22.6High risk462026-06-02
2.22.5High risk462026-06-02
2.22.4High risk462026-06-01
2.22.3High risk462026-06-01
2.22.2High risk462026-06-01
2.22.1High risk462026-05-31
2.22.0Review462026-05-31
2.20.7High risk462026-05-30
2.20.6High risk462026-05-30
2.20.5High risk462026-05-30
2.20.4High risk462026-05-30

Block this in CI

PkgRadar gates mur-common (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]