PkgRadar

Cargo · crates.io

rvimage

Rs Build Time Command: Process spawn (std::process::Command) at build time.

Why PkgRadar flagged 0.6.8

SeveritySignalEvidence
mediumRs Build Time CommandProcess spawn (std::process::Command) at build time. · rvimage-0.6.8/build.rs
mediumRemote Payloadmatched "iwr " · rvimage-0.6.8/src/rvlib/wand_util/server.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.6.8Review232026-06-16

Block this in CI

PkgRadar gates rvimage (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]