PkgRadar

Cargo · crates.io

zlayer-builder

Remote Payload: matched "curl\n"

Why PkgRadar flagged 0.12.4

SeveritySignalEvidence
mediumRemote Payloadmatched "curl\n" · zlayer-builder-0.12.4/src/dockerfile/parser.rs
mediumRemote Payloadmatched "github.com/denoland/deno/releases/download" · zlayer-builder-0.12.4/src/macos_toolchain.rs
mediumRemote Payloadmatched "curl " · zlayer-builder-0.12.4/src/windows_builder.rs
mediumRemote Payloadmatched "curl " · zlayer-builder-0.12.4/src/windows_image_resolver.rs
mediumRemote Payloadmatched "github.com/denoland/deno/releases/download" · zlayer-builder-0.12.4/src/windows_toolchain.rs
mediumRemote Payloadmatched "curl " · zlayer-builder-0.12.4/src/zimage/converter.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.12.4High risk722026-06-11
0.12.3High risk722026-06-10
0.12.2High risk842026-06-10
0.12.1High risk842026-06-10

Block this in CI

PkgRadar gates zlayer-builder (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]