PkgRadar

NuGet · nuget.org

cotton

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 0.4.26

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · Cotton.nuspec

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.26Review122026-06-04
0.4.25Review122026-06-04
0.4.23Review122026-06-04
0.4.21Review122026-05-30
0.4.20Review122026-05-29
0.4.18Review122026-05-28
0.4.17Review122026-05-27

Block this in CI

PkgRadar gates cotton (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem nuget [email protected]