PkgRadar

Cargo · crates.io

nex-pkg

Remote Payload: matched "curl "

Why PkgRadar flagged 0.25.5

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · nex-pkg-0.25.5/src/ops/forge.rs
mediumRemote Payloadmatched "curl " · nex-pkg-0.25.5/src/ops/init.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · nex-pkg-0.25.5/src/ops/profile.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.25.5High risk412026-06-01
0.25.3High risk412026-06-01
0.25.2High risk412026-06-01
0.25.1High risk412026-06-01
0.25.0High risk412026-06-01
0.24.0Review412026-05-31
0.21.7High risk412026-05-30
0.21.6High risk412026-05-30
0.21.4High risk412026-05-30
0.21.5High risk412026-05-30
0.21.3High risk412026-05-30
0.21.2High risk412026-05-30
0.21.1High risk412026-05-30
0.21.0High risk412026-05-30
0.23.0Review412026-05-30
0.22.1Review412026-05-29
0.22.0Review412026-05-29
0.21.9Review412026-05-29
0.21.8Review412026-05-29

Block this in CI

PkgRadar gates nex-pkg (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]