PkgRadar

PyPI · pypi.org

fiduswriter

Remote Payload: matched "curl "

Why PkgRadar flagged 4.1.10

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · fiduswriter-4.1.10/fiduswriter/devel/check_deps.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
4.1.10Review32026-06-12
4.1.9Review32026-06-10
4.1.8Review32026-06-10
4.1.7Review32026-06-08
4.1.6Review32026-06-08
4.1.5Review32026-06-08
4.1.4Review32026-06-07
4.1.3Review32026-06-03
4.1.2Review32026-06-02
4.1.1Review32026-06-01

Block this in CI

PkgRadar gates fiduswriter (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi fiduswriter==4.1.10