PkgRadar

PyPI · pypi.org

kernel

Remote Payload: matched "curl "

Why PkgRadar flagged 0.58.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · kernel-0.58.0/src/kernel/resources/browsers/browsers.py
mediumRemote Payloadmatched "curl " · kernel-0.58.0/src/kernel/types/browser_curl_response.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.68.0Low risk02026-06-15
0.67.0Low risk02026-06-12
0.65.0Low risk02026-06-08
0.64.0Low risk02026-06-08
0.63.0Low risk02026-06-05
0.62.0Low risk02026-06-04
0.61.0Low risk02026-06-03
0.60.0Low risk02026-06-03
0.59.0Low risk02026-06-03
0.58.0Review142026-05-27

Block this in CI

PkgRadar gates kernel (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi kernel==0.58.0