PkgRadar

Maven · repo1.maven.org

com.github.thunderz99:java-cosmos

Remote Payload: matched "cUrl "

Why PkgRadar flagged 0.8.28

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · io/github/thunderz99/cosmos/impl/postgres/PostgresImpl.java

Scanned versions

VersionVerdictScoreScanned (UTC)
0.8.28Review42026-06-10

Block this in CI

PkgRadar gates com.github.thunderz99:java-cosmos (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven com.github.thunderz99:[email protected]