PkgRadar

Cargo · crates.io

tina4

Remote Payload: matched "curl "

Why PkgRadar flagged 3.8.28

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · tina4-3.8.28/src/init.rs
mediumRemote Payloadmatched "curl " · tina4-3.8.28/src/install.rs
mediumRemote Payloadmatched "github.com/{}/releases/download" · tina4-3.8.28/src/main.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
3.8.28High risk362026-06-03
3.8.27High risk362026-06-03
3.8.26High risk362026-06-01

Block this in CI

PkgRadar gates tina4 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]