PkgRadar

Cargo · crates.io

wafrift-cli

Remote Payload: matched "curl "

Why PkgRadar flagged 0.3.1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · wafrift-cli-0.3.1/src/cache_diff_cmd.rs
mediumRemote Payloadmatched "curl " · wafrift-cli-0.3.1/src/gql_diff_cmd.rs
mediumRemote Payloadmatched "curl " · wafrift-cli-0.3.1/src/h2_diff_cmd.rs
mediumRemote Payloadmatched "curl " · wafrift-cli-0.3.1/src/main.rs
mediumRemote Payloadmatched "curl " · wafrift-cli-0.3.1/src/method_diff_cmd.rs
mediumRemote Payloadmatched "curl " · wafrift-cli-0.3.1/src/parser_diff_cmd.rs
mediumRemote Payloadmatched "curl " · wafrift-cli-0.3.1/src/scan/injection_delivery.rs
mediumRemote Payloadmatched "curl " · wafrift-cli-0.3.1/src/scan/mod.rs
mediumRemote Payloadmatched "curl " · wafrift-cli-0.3.1/src/smuggle_transport.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.1High risk502026-06-10

Block this in CI

PkgRadar gates wafrift-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]