PyPI · pypi.org
ccx-messaging
Remote Payload: matched "curl "
Why PkgRadar flagged 4.3.8
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "curl " · ccx_messaging-4.3.8/deploy/upload-ephemeral.sh |
| medium | Credential file access | matched "AWS_ACCESS_KEY" · ccx_messaging-4.3.8/ccx_messaging/utils/logging.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
4.3.8 | Review | 33 | 2026-05-29 |
4.3.7 | Review | 33 | 2026-05-29 |
Block this in CI
pkgradar gate --ecosystem pypi ccx-messaging==4.3.8