PkgRadar

PyPI · pypi.org

bright-vision-core

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 0.111.2.post3

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · bright_vision_core-0.111.2.post3/cecli/models.py
mediumRemote Payloadmatched "curl " · bright_vision_core-0.111.2.post3/scripts/sync_bright_vision.sh
mediumRemote Payloadmatched "raw.githubusercontent.com" · bright_vision_core-0.111.2.post3/scripts/tsl_pack_langs.py
mediumCredential file accessmatched "AWS_ACCESS_KEY" · bright_vision_core-0.111.2.post3/cecli/models.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.111.2.post3High risk592026-05-26
0.111.2.post2High risk2092026-05-26
0.111.2.post1High risk2092026-05-26
0.111.1.post6High risk2092026-05-26
0.111.1.post4High risk2092026-05-26
0.111.1.post5High risk2092026-05-26

Block this in CI

PkgRadar gates bright-vision-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi bright-vision-core==0.111.2.post3