PkgRadar

PyPI · pypi.org

hyperi-ci

Remote Payload: matched "github.com/gitleaks/gitleaks/releases/download"

Why PkgRadar flagged 2.6.10

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/gitleaks/gitleaks/releases/download" · hyperi_ci-2.6.10/src/hyperi_ci/quality/gitleaks.py
mediumRemote Payloadmatched "curl " · hyperi_ci-2.6.10/templates/pgo-workload/http-server.sh
mediumRemote Payloadmatched "curl " · hyperi_ci-2.6.10/templates/pgo-workload/kafka-producer.sh
mediumRemote Payloadmatched "curl " · hyperi_ci-2.6.10/templates/pgo-workload/multi-protocol.sh
mediumCredential file accessmatched ".npmrc" · hyperi_ci-2.6.10/src/hyperi_ci/languages/typescript/publish.py
mediumCredential file accessmatched "AWS_ACCESS_KEY" · hyperi_ci-2.6.10/src/hyperi_ci/publish/binaries.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.6.10High risk682026-06-16
2.6.3High risk682026-05-30
2.6.1High risk682026-05-30
2.4.2High risk682026-05-30
2.4.1High risk682026-05-30
2.3.12High risk682026-05-30
2.3.10High risk682026-05-30
2.6.4Review682026-05-29

Block this in CI

PkgRadar gates hyperi-ci (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi hyperi-ci==2.6.10