PkgRadar

PyPI · pypi.org

lbt-dragonfly

Remote Payload: matched "curl "

Why PkgRadar flagged 0.13.77

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · lbt_dragonfly-0.13.77/.github/workflows/ci.yaml

Scanned versions

VersionVerdictScoreScanned (UTC)
0.13.105Low risk02026-06-12
0.13.104Low risk02026-06-12
0.13.103Low risk02026-06-12
0.13.102Low risk02026-06-12
0.13.101Low risk02026-06-11
0.13.100Low risk02026-06-11
0.13.99Low risk02026-06-11
0.13.98Low risk02026-06-11
0.13.97Low risk02026-06-10
0.13.96Low risk02026-06-09
0.13.95Low risk02026-06-08
0.13.94Low risk02026-06-08
0.13.93Low risk02026-06-08
0.13.92Low risk02026-06-05
0.13.91Low risk02026-06-05
0.13.90Low risk02026-06-05
0.13.89Low risk02026-06-04
0.13.88Low risk02026-06-04
0.13.87Low risk02026-06-04
0.13.86Low risk02026-06-04
0.13.85Low risk02026-06-03
0.13.84Low risk02026-06-03
0.13.83Low risk02026-06-03
0.13.82Low risk02026-06-03
0.13.81Low risk02026-06-03
0.13.80Low risk02026-06-01
0.13.79Low risk02026-05-31
0.13.78Low risk02026-05-28
0.13.77Review42026-05-27
0.13.76Review42026-05-27

Block this in CI

PkgRadar gates lbt-dragonfly (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi lbt-dragonfly==0.13.77