PkgRadar

Cargo · crates.io

tree-sitter-language-pack

Rs Build Time Command Combo: Process spawn (std::process::Command) paired with network / base64 / env-token read at build time.

Why PkgRadar flagged 1.9.0-rc.54

SeveritySignalEvidence
highRs Build Time Command ComboProcess spawn (std::process::Command) paired with network / base64 / env-token read at build time. · tree-sitter-language-pack-1.9.0-rc.54/build.rs
highRs Build Time NetworkHTTP / TCP network call inside build.rs — downloads at compile time. · tree-sitter-language-pack-1.9.0-rc.54/build.rs
mediumRemote Payloadmatched "github.com/kreuzberg-dev/tree-sitter-language-pack/releases/download" · tree-sitter-language-pack-1.9.0-rc.54/src/download.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
1.9.0-rc.54High risk1122026-06-17
1.9.0-rc.53High risk1122026-06-16
1.9.0-rc.52High risk1122026-06-16
1.9.0-rc.51High risk1122026-06-15
1.9.0-rc.50High risk1122026-06-15
1.9.0-rc.49High risk1122026-06-15
1.9.0-rc.48High risk1122026-06-15
1.9.0-rc.47High risk1122026-06-14
1.9.0-rc.46High risk1122026-06-14
1.9.0-rc.45High risk1122026-06-14
1.9.0-rc.44High risk1122026-06-14
1.9.0-rc.43High risk1122026-06-14
1.9.0-rc.42High risk1122026-06-14
1.9.0-rc.41High risk1122026-06-13
1.9.0-rc.39High risk1122026-06-12
1.9.0-rc.38High risk1122026-06-12
1.9.0-rc.37High risk1122026-06-12
1.9.0-rc.36High risk1122026-06-12
1.9.0-rc.34High risk1122026-06-12
1.9.0-rc.33High risk1122026-06-11
1.9.0-rc.32High risk1122026-06-11
1.9.0-rc.30High risk1122026-06-09
1.9.0-rc.28High risk1122026-06-08
1.9.0-rc.27High risk1122026-06-08
1.9.0-rc.26High risk622026-06-08
1.9.0-rc.25High risk622026-06-07
1.9.0-rc.24High risk622026-06-07
1.9.0-rc.23High risk622026-06-06
1.9.0-rc.22High risk622026-06-06
1.9.0-rc.21High risk622026-06-06
1.9.0-rc.20High risk622026-06-05
1.9.0-rc.19High risk622026-06-04
1.9.0-rc.18High risk622026-06-03
1.9.0-rc.17High risk622026-05-30
1.9.0-rc.15High risk622026-05-30
1.9.0-rc.14High risk622026-05-30
1.9.0-rc.13High risk622026-05-30
1.9.0-rc.12High risk622026-05-30

Block this in CI

PkgRadar gates tree-sitter-language-pack (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]