PkgRadar

PyPI · pypi.org

fiberai

Remote Payload: matched "curl "

Why PkgRadar flagged 0.0.21

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · fiberai-0.0.21/.github/workflows/auto-publish.yml
mediumRemote Payloadmatched "curl " · fiberai-0.0.21/scripts/generate.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.29Low risk02026-06-15
0.0.28Low risk02026-06-15
0.0.27Low risk02026-06-11
0.0.26Low risk02026-06-05
0.0.25Low risk02026-06-04
0.0.24Low risk02026-06-01
0.0.23Low risk02026-05-29
0.0.22Low risk02026-05-29
0.0.21Review242026-05-27
0.0.20Review242026-05-26

Block this in CI

PkgRadar gates fiberai (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi fiberai==0.0.21