PkgRadar

PyPI · pypi.org

devsecops-engine-tools

Remote Payload: matched "curl "

Why PkgRadar flagged 1.154.1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · devsecops_engine_tools-1.154.1/devsecops_engine_tools/engine_sast/engine_code/src/infrastructure/driven_adapters/bearer/bearer_tool.py
mediumRemote Payloadmatched "github.com/gitleaks/gitleaks/releases/download" · devsecops_engine_tools-1.154.1/devsecops_engine_tools/engine_sast/engine_secret/src/infrastructure/driven_adapters/gitleaks/gitleaks_tool.py
mediumRemote Payloadmatched "curl " · devsecops_engine_tools-1.154.1/devsecops_engine_tools/engine_sast/engine_secret/src/infrastructure/driven_adapters/trufflehog/trufflehog_run.py
mediumCredential file accessmatched ".ssh/" · devsecops_engine_tools-1.154.1/devsecops_engine_tools/engine_utilities/ssh/managment_private_key.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.154.1High risk282026-06-03
1.154.0High risk282026-06-02

Block this in CI

PkgRadar gates devsecops-engine-tools (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi devsecops-engine-tools==1.154.1