PkgRadar

Cargo · crates.io

verg

Remote Payload: matched "curl "

Why PkgRadar flagged 0.6.5

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · verg-0.6.5/src/resources/cron.rs
mediumRemote Payloadmatched "curl " · verg-0.6.5/src/state/vars.rs
mediumRemote Payloadmatched "github.com/rvben/verg/releases/download" · verg-0.6.5/src/transport/ssh.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.6.5Review242026-06-20

Block this in CI

PkgRadar gates verg (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]