PkgRadar

PyPI · pypi.org

hive-vault

Remote Payload: matched "curl "

Why PkgRadar flagged 1.21.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · hive_vault-1.21.0/.github/workflows/release.yml
mediumObfuscation Densityhigh encoded/escaped-token density · hive_vault-1.21.0/site/package-lock.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.41.1Low risk02026-06-07
1.41.0Low risk02026-06-06
1.40.0Low risk02026-06-06
1.39.0Low risk02026-06-06
1.38.2Low risk02026-06-06
1.38.1Low risk02026-06-06
1.38.0Low risk02026-06-06
1.37.0Low risk02026-06-06
1.36.0Low risk02026-06-05
1.35.1Low risk02026-06-05
1.35.0Low risk02026-06-05
1.34.0Low risk02026-06-05
1.33.0Low risk02026-06-05
1.32.4Low risk02026-06-04
1.32.3Low risk02026-06-04
1.32.2Low risk02026-06-03
1.32.1Low risk02026-06-03
1.32.0Low risk02026-06-03
1.31.0Low risk02026-06-03
1.30.0Low risk02026-06-02
1.29.0Low risk02026-06-02
1.28.0Low risk02026-06-02
1.27.0Low risk02026-06-01
1.26.1Low risk02026-06-01
1.26.0Low risk02026-06-01
1.25.1Low risk02026-06-01
1.24.0Low risk02026-05-31
1.23.1Low risk02026-05-31
1.23.0Low risk02026-05-31
1.22.0Low risk02026-05-31
1.21.1Low risk02026-05-29
1.21.0Review242026-05-28
1.20.1Review242026-05-28
1.20.0Review242026-05-28

Block this in CI

PkgRadar gates hive-vault (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi hive-vault==1.21.0