PkgRadar

Composer · packagist.org

kitodo/publication

Remote Payload: matched "CURL "

Why PkgRadar flagged v5.3.0

SeveritySignalEvidence
mediumRemote Payloadmatched "CURL " · kitodo-kitodo-publication-cf5619f/Classes/Services/Email/Notifier.php
mediumRemote Payloadmatched "Curl " · kitodo-kitodo-publication-cf5619f/Configuration/TCA/tx_dpf_domain_model_message.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v5.3.0Review142026-06-05
v3.1.21Review62026-06-05
v3.1.20Review62026-06-04

Block this in CI

PkgRadar gates kitodo/publication (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer kitodo/[email protected]