PkgRadar

PyPI · pypi.org

astrapi-mirror

Remote Payload: matched "wget "

Why PkgRadar flagged 26.5.11

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · astrapi_mirror-26.5.11/astrapi_mirror/modules/debian/config/settings.yaml

Scanned versions

VersionVerdictScoreScanned (UTC)
26.6.14Low risk02026-06-13
26.6.13Low risk02026-06-13
26.6.12Low risk02026-06-13
26.6.11Low risk02026-06-13
26.6.10Low risk02026-06-08
26.6.9Low risk02026-06-08
26.6.8Low risk02026-06-08
26.6.7Low risk02026-06-07
26.6.6Low risk02026-06-05
26.6.5Low risk02026-06-05
26.6.4Low risk02026-06-05
26.6.3Low risk02026-06-04
26.6.2Low risk02026-06-04
26.6.1Low risk02026-06-02
26.5.13Low risk02026-05-30
26.5.12Low risk02026-05-30
26.5.11Review122026-05-27

Block this in CI

PkgRadar gates astrapi-mirror (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi astrapi-mirror==26.5.11