PkgRadar

PyPI · pypi.org

e2a

Remote Payload: matched "cURL "

Why PkgRadar flagged 2.5.0

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · e2a-2.5.0/src/e2a/v1/generated/__init__.py
mediumRemote Payloadmatched "cURL " · e2a-2.5.0/src/e2a/v1/generated/_internal.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.5.0Review242026-05-27

Block this in CI

PkgRadar gates e2a (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi e2a==2.5.0