PkgRadar

Cargo · crates.io

rotom

Rs Build Time Command: Process spawn (std::process::Command) at build time.

Why PkgRadar flagged 1.5.6

SeveritySignalEvidence
mediumRs Build Time CommandProcess spawn (std::process::Command) at build time. · rotom-1.5.6/build.rs
mediumRemote Payloadmatched "curl " · rotom-1.5.6/src/main.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
1.5.6Review522026-06-10
1.5.5Review522026-06-09
1.5.4Review522026-06-08
1.5.3Review522026-06-07
1.5.2Review522026-06-03
1.5.1Review522026-06-01
1.4.0Review522026-05-30
1.5.0Review522026-05-29
1.3.0Review422026-05-28
1.1.14Review422026-05-28
1.1.12Review422026-05-28
1.1.11Review422026-05-28
1.1.10Review422026-05-28
1.1.9Review422026-05-27
1.1.8Review422026-05-27
1.1.7Review422026-05-27
1.1.6Review422026-05-27
1.1.5Review422026-05-27
1.1.4Review422026-05-27

Block this in CI

PkgRadar gates rotom (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]