PkgRadar

PyPI · pypi.org

dkist-processing-vbi

Remote Payload: matched "curl "

Why PkgRadar flagged 1.30.12

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · dkist_processing_vbi-1.30.12/bitbucket-pipelines.yml

Scanned versions

VersionVerdictScoreScanned (UTC)
1.30.15Low risk02026-06-15
1.30.14Low risk02026-06-12
1.30.14rc1Low risk02026-06-12
1.30.13Low risk02026-06-09
1.30.12Review62026-05-27

Block this in CI

PkgRadar gates dkist-processing-vbi (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi dkist-processing-vbi==1.30.12