PkgRadar

Cargo · crates.io

purple-ssh

Rs Build Time Command: Process spawn (std::process::Command) at build time.

Why PkgRadar flagged 3.22.1

SeveritySignalEvidence
mediumRs Build Time CommandProcess spawn (std::process::Command) at build time. · purple-ssh-3.22.1/build.rs
mediumRemote Payloadmatched "curl " · purple-ssh-3.22.1/src/demo.rs
mediumRemote Payloadmatched "curl " · purple-ssh-3.22.1/src/handler/tests.rs
mediumRemote Payloadmatched "curl " · purple-ssh-3.22.1/src/key_push.rs
mediumRemote Payloadmatched "curl " · purple-ssh-3.22.1/src/tunnel_live.rs
mediumRemote Payloadmatched "curl " · purple-ssh-3.22.1/src/ui/containers_overview/tests.rs
mediumRemote Payloadmatched "curl " · purple-ssh-3.22.1/src/ui/tunnels_format.rs
mediumRemote Payloadmatched "github.com/erickochen/purple/releases/download" · purple-ssh-3.22.1/src/update.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
3.22.1High risk1642026-06-16
3.22.0High risk1642026-06-06
3.21.1High risk1592026-05-31
3.21.0Review1592026-05-31
3.20.0High risk1592026-05-30
3.19.0High risk1592026-05-30
3.18.7High risk1592026-05-30
3.18.6High risk1592026-05-30
3.18.5High risk1592026-05-30
3.18.4High risk1592026-05-30
3.20.1Review1592026-05-29

Block this in CI

PkgRadar gates purple-ssh (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]