PkgRadar

Cargo · crates.io

santa

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 0.3.4

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · santa-0.3.4/src/bin/collect_packages.rs
mediumRemote Payloadmatched "curl " · santa-0.3.4/src/commands/tests.rs
mediumRemote Payloadmatched "curl " · santa-0.3.4/src/configuration.rs
mediumRemote Payloadmatched "curl " · santa-0.3.4/src/data.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · santa-0.3.4/src/data_layers.rs
mediumRemote Payloadmatched "curl " · santa-0.3.4/src/script_generator.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · santa-0.3.4/src/source_layers.rs
mediumRemote Payloadmatched "curl " · santa-0.3.4/src/sources.rs
mediumRemote Payloadmatched "curl\n" · santa-0.3.4/src/tests.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.4High risk682026-06-04

Block this in CI

PkgRadar gates santa (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]