PkgRadar

PyPI · pypi.org

daylily-ephemeral-cluster

Remote Payload: matched "wget "

Why PkgRadar flagged 5.1.30

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · daylily_ec/resources/payload/bin/check_prereq_sw.sh
mediumRemote Payloadmatched "curl\n" · daylily_ec/resources/payload/bin/test_region_accel_endpoint.sh
mediumRemote Payloadmatched "curl " · daylily_ec/resources/payload/bin/aws/check_instance_type.sh
mediumRemote Payloadmatched "curl " · daylily_ec/resources/payload/config/day_cluster/post_install_tags.sh
mediumRemote Payloadmatched "curl " · daylily_ec/resources/payload/config/day_cluster/post_install_ubuntu_combined.sh
mediumRemote Payloadmatched "wget " · daylily_ec/resources/payload/quarantine/config/day/day_env_installer.sh
mediumCredential file accessmatched ".aws/" · daylily_ec/resources/payload/bin/daylily-analysis-samples-to-manifest-new.py

Scanned versions

VersionVerdictScoreScanned (UTC)
5.1.30High risk872026-06-03
5.1.29High risk872026-06-03
5.1.21High risk872026-06-02
5.1.17High risk872026-06-01

Block this in CI

PkgRadar gates daylily-ephemeral-cluster (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi daylily-ephemeral-cluster==5.1.30