PkgRadar

PyPI · pypi.org

boto3-assist

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 0.63.0

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · boto3_assist-0.63.0/publish_to_pypi.sh
mediumRemote Payloadmatched "curl " · boto3_assist-0.63.0/pysetup.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.63.0Review372026-06-04
0.62.0Review372026-05-29

Block this in CI

PkgRadar gates boto3-assist (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi boto3-assist==0.63.0