PkgRadar

PyPI · pypi.org

nebulacode

Remote Payload: matched "curl "

Why PkgRadar flagged 0.13.6

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · nebulacode-0.13.6/deploy.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.13.6Review172026-06-12
0.13.5Review172026-06-12
0.13.4Review52026-06-07
0.13.3Review52026-06-06
0.13.2Review52026-06-05
0.13.1Review52026-06-05
0.13.0Review52026-06-05
0.12.1Review52026-06-05
0.12.0Review52026-06-05
0.11.0Review52026-06-04
0.10.2Review52026-06-03
0.10.1Review52026-06-03
0.10.0Review52026-06-03
0.9.1Review52026-06-03
0.9.0Review52026-06-02
0.8.0Review52026-06-01
0.7.0Review52026-05-26
0.6.0Review52026-05-26

Block this in CI

PkgRadar gates nebulacode (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi nebulacode==0.13.6