PkgRadar

Cargo · crates.io

oxios

Remote Payload: matched "github.com/a7garden/oxios/releases/download"

Why PkgRadar flagged 1.2.0

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/a7garden/oxios/releases/download" · oxios-1.2.0/src/kernel.rs
mediumRemote Payloadmatched "github.com/{GITHUB_REPO}/releases/download" · oxios-1.2.0/src/web_dist.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
1.2.0Review242026-06-06
1.1.0Review242026-06-06
1.0.2Review242026-05-31
1.0.1Review122026-05-31
1.0.0Review122026-05-31

Block this in CI

PkgRadar gates oxios (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]