PkgRadar

PyPI · pypi.org

jusfltuls

Remote Payload: matched "curl "

Why PkgRadar flagged 0.4.27

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · jusfltuls-0.4.27/src/jusfltuls/codetools/extract_page.sh
mediumRemote Payloadmatched "github.com/restic/restic/releases/download" · jusfltuls-0.4.27/src/jusfltuls/mcrc/ui.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.27Review242026-06-12
0.4.26Review242026-06-11
0.4.25Review242026-06-08
0.4.24Review242026-06-04
0.4.23Review242026-06-04
0.4.22Review242026-06-04
0.4.21Review242026-06-04
0.4.20Review242026-06-04
0.4.19Review242026-06-04
0.4.18Review242026-06-04
0.4.17Review242026-06-04
0.4.16Review242026-06-04
0.4.15Review242026-06-02

Block this in CI

PkgRadar gates jusfltuls (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi jusfltuls==0.4.27