PkgRadar

PyPI · pypi.org

alfard

Remote Payload: matched "curl "

Why PkgRadar flagged 0.1.28

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · alfard-0.1.28/alfard/setup/dependencies.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.28Review122026-06-15
0.1.27Review122026-06-12
0.1.26Review122026-06-05
0.1.25Review122026-06-05
0.1.24Review122026-06-02
0.1.23Review122026-06-02
0.1.22Review122026-06-02
0.1.21Review122026-06-02
0.1.20Review122026-06-02
0.1.19Review122026-06-01
0.1.18Review122026-06-01
0.1.17Review122026-06-01
0.1.16Review122026-06-01
0.1.15Review122026-05-31
0.1.14Review122026-05-30
0.1.13Review122026-05-30
0.1.12Review122026-05-29
0.1.11Review122026-05-29
0.1.10Review172026-05-28
0.1.9Review172026-05-28
0.1.8Review172026-05-28
0.1.7Review172026-05-28
0.1.6Review172026-05-28
0.1.5Review172026-05-28
0.1.4Review412026-05-27

Block this in CI

PkgRadar gates alfard (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi alfard==0.1.28