PkgRadar

PyPI · pypi.org

kumoai

Remote Payload: matched "curl "

Why PkgRadar flagged 2.23.0.dev202605271834

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · kumoai/client/client.py
mediumRemote Payloadmatched "raw.githubusercontent.com" · kumoai/rfm/relbench.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.23.0.dev202606121843Low risk02026-06-13
2.23.0.dev202606111848Low risk02026-06-12
2.23.0.dev202606101849Low risk02026-06-11
2.23.0.dev202606091843Low risk02026-06-10
2.23.0.dev202606081837Low risk02026-06-09
2.23.0.dev202606071847Low risk02026-06-08
2.23.0.dev202606061844Low risk02026-06-07
2.23.0.dev202606051838Low risk02026-06-06
2.23.0.dev202606041843Low risk02026-06-05
2.23.0.dev202606031853Low risk02026-06-04
2.23.0.dev202606021854Low risk02026-06-03
2.23.0.dev202606011849Low risk02026-06-02
2.23.0.dev202605311846Low risk02026-06-01
2.23.0.dev202605301842Low risk02026-05-31
2.23.0.dev202605291836Low risk02026-05-30
2.23.0.dev202605281839Low risk02026-05-29
2.23.0.dev202605271834Review142026-05-28
2.23.0.dev202605261842Review142026-05-27

Block this in CI

PkgRadar gates kumoai (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi kumoai==2.23.0.dev202605271834