PkgRadar

PyPI · pypi.org

codegraphcontext

Remote Payload: matched "wget "

Why PkgRadar flagged 0.4.12

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · codegraphcontext-0.4.12/src/codegraphcontext/cli/setup_wizard.py
mediumCredential file accessmatched "GITHUB_TOKEN" · codegraphcontext-0.4.12/src/codegraphcontext/core/bundle_registry.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.1Low risk02026-06-12
0.4.18Low risk02026-06-10
0.4.17Low risk02026-06-08
0.4.16Low risk02026-06-07
0.4.15Low risk02026-06-07
0.4.14Low risk02026-06-07
0.4.13Low risk02026-06-01
0.4.12Review152026-05-26

Block this in CI

PkgRadar gates codegraphcontext (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi codegraphcontext==0.4.12