PkgRadar

PyPI · pypi.org

c2cgeoportal-geoportal

Remote Payload: matched "curl "

Why PkgRadar flagged 2.9.0.486

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · c2cgeoportal_geoportal/scripts/c2cupgrade.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.9.0.497Low risk02026-06-11
2.9.0.496Low risk02026-06-11
2.9.0.495Low risk02026-06-11
2.9.0.494Low risk02026-06-11
2.8.1.340Low risk02026-06-10
2.9.0.493Low risk02026-06-10
2.9.0.492Low risk02026-06-05
2.8.1.339Low risk02026-06-04
2.8.1.338Low risk02026-06-03
2.9.0.490Low risk02026-06-02
2.8.1.337Low risk02026-06-02
2.9.0.489Low risk02026-06-01
2.9.0.488Low risk02026-06-01
2.9.0.487Low risk02026-06-01
2.8.1.336Low risk02026-06-01
2.9.0.486Review52026-05-27
2.8.1.335Review52026-05-27
2.9.0.485Review52026-05-27
2.8.1.334Review52026-05-27
2.9.0.484Review52026-05-27
2.9.0.483Review212026-05-26

Block this in CI

PkgRadar gates c2cgeoportal-geoportal (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi c2cgeoportal-geoportal==2.9.0.486