PkgRadar

PyPI · pypi.org

easy-local-features

Remote Payload: matched "wget "

Why PkgRadar flagged 0.8.28

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · easy_local_features-0.8.28/src/easy_local_features/datasets/download.py
mediumRemote Payloadmatched "wget " · easy_local_features-0.8.28/src/easy_local_features/submodules/git_r2d2/download_training_data.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.8.28Review122026-06-05
0.8.27Review122026-05-30

Block this in CI

PkgRadar gates easy-local-features (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi easy-local-features==0.8.28