PkgRadar

Maven · repo1.maven.org

com.aliyun:dingtalk

Remote Payload: matched "cUrl "

Why PkgRadar flagged 2.2.54

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · com/aliyun/dingtalkesign_1_0/models/GetSignNoticeUrlResponseBody.java
mediumRemote Payloadmatched "cUrl " · com/aliyun/dingtalkesign_1_0/models/GetProcessStartUrlRequest.java
mediumRemote Payloadmatched "cUrl " · com/aliyun/dingtalkesign_1_0/models/GetUserRealnameUrlResponseBody.java
mediumRemote Payloadmatched "cUrl " · com/aliyun/dingtalkesign_1_0/models/GetProcessStartUrlResponseBody.java
mediumRemote Payloadmatched "cUrl " · com/aliyun/dingtalkesign_1_0/models/GetCorpRealnameUrlResponseBody.java
mediumRemote Payloadmatched "cUrl " · com/aliyun/dingtalkesign_1_0/models/AuthUrlResponseBody.java
mediumRemote Payloadmatched "cUrl " · com/aliyun/dingtalkblackboard_1_0/models/GetBlackboardResponseBody.java
mediumRemote Payloadmatched "cUrl " · com/aliyun/dingtalkesign_2_0/models/GetExecuteUrlResponseBody.java
mediumRemote Payloadmatched "cUrl " · com/aliyun/dingtalkesign_2_0/models/ProcessStartResponseBody.java
mediumRemote Payloadmatched "cUrl " · com/aliyun/dingtalkesign_2_0/models/UsersRealnameResponseBody.java
mediumRemote Payloadmatched "cUrl " · com/aliyun/dingtalkesign_2_0/models/CorpRealnameResponseBody.java
mediumRemote Payloadmatched "cUrl " · com/aliyun/dingtalkesign_2_0/models/GetAuthUrlResponseBody.java

Scanned versions

VersionVerdictScoreScanned (UTC)
2.2.54High risk252026-06-10

Block this in CI

PkgRadar gates com.aliyun:dingtalk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven com.aliyun:[email protected]