PkgRadar

PyPI · pypi.org

dcap-qvl

Remote Payload: matched "github.com/org/repo/releases/download"

Why PkgRadar flagged 0.5.2

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/org/repo/releases/download" · dcap_qvl-0.5.2/golang-bindings/cmd/install-lib/main_test.go

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.2Review82026-05-31

Block this in CI

PkgRadar gates dcap-qvl (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi dcap-qvl==0.5.2