PkgRadar

PyPI · pypi.org

gsctl

Remote Payload: matched "curl "

Why PkgRadar flagged 0.31.0a20260527

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · graphscope/gsctl/scripts/install_deps.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.31.0a20260612Low risk02026-06-12
0.31.0a20260611Low risk02026-06-11
0.31.0a20260610Low risk02026-06-10
0.31.0a20260609Low risk02026-06-09
0.31.0a20260608Low risk02026-06-08
0.31.0a20260607Low risk02026-06-07
0.31.0a20260606Low risk02026-06-06
0.31.0a20260605Low risk02026-06-05
0.31.0a20260604Low risk02026-06-04
0.31.0a20260603Low risk02026-06-03
0.31.0a20260602Low risk02026-06-02
0.31.0a20260601Low risk02026-06-01
0.31.0a20260531Low risk02026-05-31
0.31.0a20260530Low risk02026-05-30
0.31.0a20260529Low risk02026-05-29
0.31.0a20260528Low risk02026-05-28
0.31.0a20260527Review62026-05-27
0.31.0a20260526Review162026-05-26

Block this in CI

PkgRadar gates gsctl (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi gsctl==0.31.0a20260527