Pub (Dart) · pub.dev
libsignal
Dart Process Http Combo: Process spawn paired with HTTP fetch — typical fetch-and-run shape.
Why PkgRadar flagged 5.0.5
| Severity | Signal | Evidence |
|---|---|---|
| medium | Dart Process Http Combo | Process spawn paired with HTTP fetch — typical fetch-and-run shape. · hook/build.dart |
| medium | Remote Payload | matched "github.com/$_githubRepo/releases/download" · hook/build.dart |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
5.0.5 | Review | 30 | 2026-06-12 |
5.0.4 | Review | 30 | 2026-06-10 |
5.0.3 | Review | 30 | 2026-06-04 |
5.0.2 | Review | 30 | 2026-05-31 |
Block this in CI
pkgradar gate --ecosystem pub [email protected]