PkgRadar

PyPI · pypi.org

benchmark-qed

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 0.3.0.post16.dev0

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · benchmark_qed/data/cli.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.0.post16.dev0Review172026-05-27
0.4.0Review172026-05-27

Block this in CI

PkgRadar gates benchmark-qed (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi benchmark-qed==0.3.0.post16.dev0