PkgRadar

Cargo · crates.io

rlx-mlx-sys

Rs Build Time Command: Process spawn (std::process::Command) at build time.

Why PkgRadar flagged 0.2.6

SeveritySignalEvidence
mediumRs Build Time CommandProcess spawn (std::process::Command) at build time. · rlx-mlx-sys-0.2.6/build.rs
mediumRemote Payloadmatched "github.com/OpenMathLib/OpenBLAS/releases/download" · rlx-mlx-sys-0.2.6/build.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.6Review422026-06-10
0.2.5Review422026-06-10
0.2.4Review422026-06-09
0.2.3Review422026-06-09
0.2.2Review302026-05-29
0.2.1Review302026-05-28
0.2.0Review302026-05-27

Block this in CI

PkgRadar gates rlx-mlx-sys (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]
rlx-mlx-sys — Cargo security scan | PkgRadar