PkgRadar

Cargo · crates.io

pathlint

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 0.0.37

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · pathlint-0.0.37/src/bin/gen_check_schema.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · pathlint-0.0.37/src/bin/gen_doctor_schema.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · pathlint-0.0.37/src/bin/gen_schema.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · pathlint-0.0.37/src/bin/gen_sort_schema.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · pathlint-0.0.37/src/bin/gen_trace_schema.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.37High risk502026-06-14
0.0.35High risk502026-06-09
0.0.33High risk502026-06-01

Block this in CI

PkgRadar gates pathlint (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]