PkgRadar

PyPI · pypi.org

gpu-dev

Remote Payload: matched "curl "

Why PkgRadar flagged 0.7.12

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · gpu_dev-0.7.12/terraform-gpu-devservers/migrations/run_backfill.sh
mediumRemote Payloadmatched "wget\n\n" · gpu_dev-0.7.12/terraform-gpu-devservers/templates/al2023-cpu-user-data.sh
mediumRemote Payloadmatched "curl " · gpu_dev-0.7.12/terraform-gpu-devservers/templates/al2023-user-data.sh
mediumRemote Payloadmatched "wget " · gpu_dev-0.7.12/terraform-gpu-devservers/templates/user-data-self-managed.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.7.12High risk732026-06-09
0.7.11High risk732026-06-02
0.7.10High risk732026-06-02
0.6.6High risk682026-05-30
0.7.6Review682026-05-30
0.7.5Review682026-05-30
0.7.4Review682026-05-30
0.7.3Review682026-05-30
0.7.2Review682026-05-30
0.7.1Review682026-05-30
0.7.0Review52026-05-30

Block this in CI

PkgRadar gates gpu-dev (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi gpu-dev==0.7.12