PkgRadar

Cargo · crates.io

ptuf

Remote Payload: matched "curl "

Why PkgRadar flagged 0.3.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · ptuf-0.3.0/src/audit/redaction.rs
mediumRemote Payloadmatched "curl\n " · ptuf-0.3.0/src/cli/run.rs
mediumRemote Payloadmatched "curl\n " · ptuf-0.3.0/src/engine/filter.rs
mediumRemote Payloadmatched "curl\n " · ptuf-0.3.0/src/engine/mod.rs
mediumRemote Payloadmatched "curl\n " · ptuf-0.3.0/src/engine/test_support.rs
mediumRemote Payloadmatched "curl " · ptuf-0.3.0/src/facts/shell.rs
mediumRemote Payloadmatched "curl " · ptuf-0.3.0/src/plugin/dsl.rs
mediumRemote Payloadmatched "curl\n " · ptuf-0.3.0/src/plugin/runner.rs
mediumRemote Payloadmatched "curl " · ptuf-0.3.0/src/rules/mod.rs
mediumRemote Payloadmatched "curl " · ptuf-0.3.0/src/rules/remote_pipe.rs
mediumRemote Payloadmatched "curl " · ptuf-0.3.0/src/rules/sensitive_net.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.0High risk1502026-06-01
0.2.0High risk1502026-05-30

Block this in CI

PkgRadar gates ptuf (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]