PkgRadar

PyPI · pypi.org

chalkcompute

Remote Payload: matched "curl "

Why PkgRadar flagged 1.5.17

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · chalkcompute-1.5.17/chalkcompute/_image.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.1.3Low risk02026-06-08
2.1.2Low risk02026-06-02
2.1.1Low risk02026-06-02
2.1.0Low risk02026-06-02
2.0.1Low risk02026-06-02
2.0.0Low risk02026-05-30
1.5.17Review172026-05-27
1.5.16Review322026-05-26
1.5.15Review322026-05-26

Block this in CI

PkgRadar gates chalkcompute (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi chalkcompute==1.5.17