PkgRadar

Cargo · crates.io

omni-dev

Remote Payload: matched "github.com/k2-fsa/sherpa-onnx/releases/download"

Why PkgRadar flagged 0.29.0

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/k2-fsa/sherpa-onnx/releases/download" · omni-dev-0.29.0/src/voice/models.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.29.0Review82026-06-12
0.28.0Review82026-06-01

Block this in CI

PkgRadar gates omni-dev (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]