PkgRadar

Cargo · crates.io

vizier

Rs Build Time Command: Process spawn (std::process::Command) at build time.

Why PkgRadar flagged 0.10.0-rc.3

SeveritySignalEvidence
mediumRs Build Time CommandProcess spawn (std::process::Command) at build time. · vizier-0.10.0-rc.3/build.rs
mediumRemote Payloadmatched "github.com/k2-fsa/sherpa-onnx/releases/download" · vizier-0.10.0-rc.3/src/utils/kitten.rs
mediumRemote Payloadmatched "github.com/k2-fsa/sherpa-onnx/releases/download" · vizier-0.10.0-rc.3/src/utils/sense_voice.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.10.0-rc.3Review542026-06-10
0.10.0-rc.2Review422026-06-08
0.10.0-rc.1Review422026-06-07
0.9.2Review302026-06-07
0.9.1Review302026-06-06
0.9.0Review302026-06-06
0.9.0-rc.1Review302026-06-04
0.8.3Review302026-06-03
0.8.2Review302026-06-02
0.8.1Review302026-06-02
0.8.0Review302026-06-02
0.7.0Review302026-05-31

Block this in CI

PkgRadar gates vizier (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]
vizier — Cargo security scan | PkgRadar