PkgRadar

Cargo · crates.io

nu-lint

Remote Payload: matched "curl "

Why PkgRadar flagged 1.2.1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · nu-lint-1.2.1/src/fix.rs
mediumRemote Payloadmatched "curl " · nu-lint-1.2.1/src/rules/add_hat_external_commands/detect_bad.rs
mediumRemote Payloadmatched "curl " · nu-lint-1.2.1/src/rules/check_complete_exit_code/detect_bad.rs
mediumRemote Payloadmatched "curl " · nu-lint-1.2.1/src/rules/external_tools/curl_to_http/detect_bad.rs
mediumRemote Payloadmatched "curl " · nu-lint-1.2.1/src/rules/external_tools/curl_to_http/generated_fix.rs
mediumRemote Payloadmatched "curl " · nu-lint-1.2.1/src/rules/external_tools/curl_to_http/mod.rs
mediumRemote Payloadmatched "curl " · nu-lint-1.2.1/src/rules/external_tools/jq_to_nu_pipeline/detect_bad.rs
mediumRemote Payloadmatched "curl " · nu-lint-1.2.1/src/rules/external_tools/jq_to_nu_pipeline/ignore_good.rs
mediumRemote Payloadmatched "wget " · nu-lint-1.2.1/src/rules/external_tools/wget_to_http_get/detect_bad.rs
mediumRemote Payloadmatched "wget " · nu-lint-1.2.1/src/rules/external_tools/wget_to_http_get/generated_fix.rs
mediumRemote Payloadmatched "wget " · nu-lint-1.2.1/src/rules/external_tools/wget_to_http_get/mod.rs
mediumRemote Payloadmatched "curl " · nu-lint-1.2.1/src/rules/fragile_last_exit_code/detect_bad.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
1.2.1High risk702026-06-02
1.2.0High risk702026-06-02

Block this in CI

PkgRadar gates nu-lint (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]