PkgRadar

Cargo · crates.io

uzor-fonts

Rs Build Time Command: Process spawn (std::process::Command) at build time.

Why PkgRadar flagged 1.4.13

SeveritySignalEvidence
mediumRs Build Time CommandProcess spawn (std::process::Command) at build time. · uzor-fonts-1.4.13/build.rs
mediumRemote Payloadmatched "github.com/ZENG3LD/uzor/releases/download" · uzor-fonts-1.4.13/build.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
1.4.13Review422026-06-13
1.4.12Review422026-06-12
1.4.11Review422026-06-10
1.4.10Review422026-06-09
1.4.9Review422026-06-09
1.4.7Review422026-06-09
1.4.6Review422026-06-04
1.4.5Review422026-06-04
1.4.4Review422026-06-03
1.4.3Review422026-06-03
1.4.2Review422026-06-03
1.4.1Review422026-06-03
1.4.0Review422026-06-03
1.3.6Review422026-05-31
1.3.5Review422026-05-29
1.3.4Review422026-05-29
1.3.3Review422026-05-28

Block this in CI

PkgRadar gates uzor-fonts (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]