PkgRadar

PyPI · pypi.org

geoprepare

Remote Payload: matched "curl "

Why PkgRadar flagged 0.6.248

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · geoprepare-0.6.248/geoprepare/datasets/CHIRPS.py
mediumRemote Payloadmatched "curl " · geoprepare-0.6.248/geoprepare/datasets/CHIRTS_ERA5.py
mediumRemote Payloadmatched "wget\n" · geoprepare-0.6.248/geoprepare/datasets/CPC.py
mediumRemote Payloadmatched "wget\n" · geoprepare-0.6.248/geoprepare/datasets/ESI.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.6.270Low risk02026-06-09
0.6.269Low risk02026-06-08
0.6.268Low risk02026-06-07
0.6.267Low risk02026-06-07
0.6.266Low risk02026-06-07
0.6.265Low risk02026-06-07
0.6.264Low risk02026-06-05
0.6.263Low risk02026-06-04
0.6.262Low risk02026-06-04
0.6.261Low risk02026-05-31
0.6.260Low risk02026-05-31
0.6.253Low risk02026-05-29
0.6.252Low risk02026-05-29
0.6.251Low risk02026-05-29
0.6.250Low risk02026-05-29
0.6.249Low risk02026-05-29
0.6.248Review242026-05-28
0.6.247Review242026-05-27

Block this in CI

PkgRadar gates geoprepare (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi geoprepare==0.6.248