PkgRadar

PyPI · pypi.org

marge-mri

Remote Payload: matched "wget "

Why PkgRadar flagged 1.0.0rc2

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · marge_mri-1.0.0rc2/marge/marcos_install.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.0rc2Review112026-06-06
1.0.0rc1Review112026-06-06
1.0.0b5Review112026-06-06

Block this in CI

PkgRadar gates marge-mri (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi marge-mri==1.0.0rc2
marge-mri — PyPI security scan | PkgRadar