PkgRadar

PyPI · pypi.org

modal

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 1.4.4.dev9

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · modal-1.4.4.dev9/modal/cli/programs/vscode.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.5.1.dev7Low risk02026-06-17
1.5.1.dev6Low risk02026-06-16
1.5.1.dev5Low risk02026-06-15
1.5.1.dev4Low risk02026-06-14
1.5.1.dev3Low risk02026-06-13
1.5.1.dev2Low risk02026-06-12
1.5.1.dev1Low risk02026-06-11
1.5.1.dev0Low risk02026-06-10
1.5.0Low risk02026-06-09
1.4.4.dev22Low risk02026-06-09
1.4.4.dev21Low risk02026-06-09
1.4.4.dev20Low risk02026-06-08
1.4.4.dev19Low risk02026-06-07
1.4.4.dev18Low risk02026-06-06
1.4.4.dev17Low risk02026-06-05
1.4.4.dev16Low risk02026-06-04
1.4.4.dev15Low risk02026-06-03
1.4.4.dev14Low risk02026-06-02
1.4.4.dev13Low risk02026-06-01
1.4.4.dev12Low risk02026-05-31
1.4.4.dev11Low risk02026-05-30
1.4.4.dev10Low risk02026-05-29
1.4.4.dev9Review132026-05-28
1.4.4.dev8Review132026-05-27

Block this in CI

PkgRadar gates modal (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi modal==1.4.4.dev9