PkgRadar

Cargo · crates.io

syn

Rs Build Time Command: Process spawn (std::process::Command) at build time.

Why PkgRadar flagged 1.0.109

SeveritySignalEvidence
mediumRs Build Time CommandProcess spawn (std::process::Command) at build time. · syn-1.0.109/build.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.118Low risk02026-06-16
1.0.109Review92026-06-15
2.0.114Low risk02026-06-15
2.0.38Low risk02026-06-01
2.0.57Low risk02026-06-01
2.0.48Low risk02026-06-01
2.0.117Low risk02026-06-01

Block this in CI

PkgRadar gates syn (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]
syn — Cargo security scan | PkgRadar