PkgRadar

Cargo · crates.io

node-app-build

Remote Payload: matched "curl "

Why PkgRadar flagged 5.26.3

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · node-app-build-5.26.3/src/commands/dev/host/deb.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
5.26.3Review122026-06-02
5.26.2Review122026-06-02
5.26.1Review122026-06-01
5.26.0Review122026-06-01
5.25.1Review122026-06-01
5.25.0Review122026-05-31
5.24.0Review122026-05-30
5.23.2Review122026-05-27

Block this in CI

PkgRadar gates node-app-build (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]