PkgRadar

Cargo · crates.io

opensymphony

Credential File Packaged: opensymphony-1.9.2/.npmrc

Why PkgRadar flagged 1.9.2

SeveritySignalEvidence
highCredential File Packagedopensymphony-1.9.2/.npmrc · opensymphony-1.9.2/.npmrc
mediumRemote Payloadmatched "raw.githubusercontent.com" · opensymphony-1.9.2/crates/opensymphony-cli/src/init_repo.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
1.9.2High risk472026-06-15
1.9.1High risk472026-06-14
1.9.0High risk472026-06-14
1.8.0High risk472026-06-08
1.7.3High risk472026-06-03
1.7.2High risk472026-06-01
1.7.1High risk472026-05-31
1.7.0High risk472026-05-31

Block this in CI

PkgRadar gates opensymphony (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]