PkgRadar

PyPI · pypi.org

cdk-factory

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 1.8.1

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · cdk_factory-1.8.1/publish_to_pypi.sh
mediumRemote Payloadmatched "curl " · cdk_factory-1.8.1/pysetup.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.8.1Review272026-06-11
1.8.0Review272026-06-09
1.7.7Review272026-06-08
1.7.6Review272026-06-04
1.7.5Review272026-06-04
1.7.4Review272026-06-03
1.7.3Review272026-06-02
1.7.2Review272026-05-31
1.7.1Review272026-05-31
1.7.0Review272026-05-31
1.6.12Review272026-05-31
1.6.11Review272026-05-30
1.6.6Review272026-05-30
1.6.10Review272026-05-30
1.6.9Review272026-05-29
1.6.8Review272026-05-29
1.6.7Review272026-05-28

Block this in CI

PkgRadar gates cdk-factory (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi cdk-factory==1.8.1