PkgRadar

PyPI · pypi.org

matrix-synapse

Remote Payload: matched "wget "

Why PkgRadar flagged 1.155.0rc1

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · matrix_synapse-1.155.0rc1/scripts-dev/complement.sh
mediumRemote Payloadmatched "curl " · matrix_synapse-1.155.0rc1/scripts-dev/next_github_number.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.155.0rc1Review72026-06-09
1.154.0Review72026-06-04
1.154.0rc1Review112026-05-27

Block this in CI

PkgRadar gates matrix-synapse (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi matrix-synapse==1.155.0rc1
matrix-synapse — PyPI security scan | PkgRadar