PkgRadar

PyPI · pypi.org

little-loops

Remote Payload: matched "curl\n "

Why PkgRadar flagged 1.111.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl\n " · little_loops-1.111.0/little_loops/parallel/tasks/health-check.yaml

Scanned versions

VersionVerdictScoreScanned (UTC)
1.122.0Low risk02026-06-13
1.121.0Low risk02026-06-11
1.120.0Low risk02026-06-10
1.119.0Low risk02026-06-09
1.118.0Low risk02026-06-08
1.117.0Low risk02026-06-07
1.116.0Low risk02026-06-05
1.115.0Low risk02026-06-03
1.114.0Low risk02026-06-02
1.113.0Low risk02026-05-31
1.112.0Low risk02026-05-28
1.111.0Review122026-05-27

Block this in CI

PkgRadar gates little-loops (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi little-loops==1.111.0