PkgRadar

Cargo · crates.io

prek

Rs Build Time Command: Process spawn (std::process::Command) at build time.

Why PkgRadar flagged 0.4.4

SeveritySignalEvidence
mediumRs Build Time CommandProcess spawn (std::process::Command) at build time. · prek-0.4.4/build.rs
mediumRemote Payloadmatched "github.com/oven-sh/bun/releases/download" · prek-0.4.4/src/languages/bun/installer.rs
mediumRemote Payloadmatched "github.com/astral-sh/uv/releases/download" · prek-0.4.4/src/languages/python/uv.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.4Review412026-06-04

Block this in CI

PkgRadar gates prek (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]