PkgRadar

PyPI · pypi.org

funasr

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 1.3.7

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · funasr-1.3.7/runtime/deploy_tools/funasr-runtime-deploy-offline-cpu-en.sh
mediumRemote Payloadmatched "raw.githubusercontent.com" · funasr-1.3.7/runtime/deploy_tools/funasr-runtime-deploy-offline-cpu-zh.sh
mediumRemote Payloadmatched "raw.githubusercontent.com" · funasr-1.3.7/runtime/deploy_tools/funasr-runtime-deploy-online-cpu-zh.sh
mediumRemote Payloadmatched "curl " · funasr-1.3.7/runtime/deploy_tools/install_docker.sh
mediumRemote Payloadmatched "wget " · funasr-1.3.7/runtime/onnxruntime/third_party/download_ffmpeg.sh
mediumRemote Payloadmatched "wget " · funasr-1.3.7/runtime/onnxruntime/third_party/download_onnxruntime.sh
mediumRemote Payloadmatched "wget " · funasr-1.3.7/runtime/onnxruntime/third_party/openfst/_import_release.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.3.7High risk422026-05-30
1.3.6High risk422026-05-30
1.3.5High risk422026-05-30
1.3.9Review422026-05-29
1.3.8Review422026-05-29

Block this in CI

PkgRadar gates funasr (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi funasr==1.3.7
funasr — PyPI security scan | PkgRadar