PkgRadar

Cargo · crates.io

tokensave

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 6.4.0

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · tokensave-6.4.0/src/accounting/pricing.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
6.4.0Review122026-06-16
6.3.3Review122026-06-15
6.3.2Review122026-06-15
6.3.1Review122026-06-10
6.3.0Review122026-06-09
6.2.0Review122026-06-09
6.1.4Review122026-06-07
6.1.3Review122026-06-04
6.1.2Review122026-05-30

Block this in CI

PkgRadar gates tokensave (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]