PkgRadar

PyPI · pypi.org

chain-signer

Remote Payload: matched "curl "

Why PkgRadar flagged 0.5.31

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · chain_signer-0.5.31/tools/notify.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.31Review172026-06-12
0.5.30Review172026-06-12
0.5.29Review172026-06-11
0.5.28Review172026-06-10
0.5.27Review172026-06-09
0.5.26Review172026-06-09
0.5.25Review172026-06-09
0.5.24Review172026-06-08
0.5.23Review172026-06-08
0.5.22Review172026-06-08
0.5.21Review172026-06-08
0.5.20Review172026-06-08
0.5.19Review172026-06-08
0.5.18Review172026-06-07
0.5.17Review172026-06-07
0.5.16Review172026-06-07
0.5.15Review172026-06-07
0.5.14Review172026-06-07
0.5.13Review172026-06-07
0.5.12Review172026-06-06
0.5.11Review172026-06-06
0.5.10Review172026-06-06
0.5.9Review172026-06-06
0.5.8Review172026-06-04
0.5.7Review172026-06-04
0.5.6Review172026-06-04
0.5.5Review172026-06-04
0.5.4Review172026-06-04
0.5.3Review172026-06-03
0.5.2Review172026-06-03
0.5.1Review172026-06-03
0.5.0Review172026-06-03
0.4.3Review172026-06-03
0.4.2Review172026-06-03
0.4.1Review172026-06-03
0.4.0Review172026-06-03
0.3.4Review172026-06-03
0.3.3Review172026-06-03
0.3.2Review172026-06-03
0.3.1Review172026-06-03
0.3.0Review172026-06-03
0.2.8Review172026-06-02
0.2.7Review172026-06-02
0.2.6Review172026-06-02
0.2.5Review172026-06-02
0.2.4Review172026-06-02
0.2.3Review172026-06-02
0.2.2Review172026-06-02
0.2.1Review172026-06-02
0.2.0Review172026-06-02
0.1.16Review172026-06-02
0.1.15Review172026-06-02
0.1.14Review172026-06-02
0.1.13Review172026-06-02
0.1.12Review172026-06-02
0.1.11Review172026-06-02
0.1.10Review172026-06-01
0.1.9Review172026-06-01
0.1.8Review172026-06-01
0.1.7Review172026-06-01
0.1.6Review172026-06-01
0.1.5Review172026-06-01
0.1.4Review172026-06-01
0.1.3Low risk02026-06-01
0.1.2Review172026-06-01
0.1.1Review172026-06-01
0.1.0Review172026-06-01

Block this in CI

PkgRadar gates chain-signer (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi chain-signer==0.5.31