PkgRadar

PyPI · pypi.org

nl-code

Remote Payload: matched "curl "

Why PkgRadar flagged 0.7.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · nl_code-0.7.0/ui/dataset-explorer/frontend/node_modules/playwright-core/bin/reinstall_chrome_beta_mac.sh
mediumRemote Payloadmatched "curl " · nl_code-0.7.0/ui/dataset-explorer/frontend/node_modules/playwright-core/bin/reinstall_chrome_stable_mac.sh
mediumRemote Payloadmatched "curl " · nl_code-0.7.0/ui/dataset-explorer/frontend/node_modules/playwright-core/bin/reinstall_msedge_beta_mac.sh
mediumRemote Payloadmatched "curl " · nl_code-0.7.0/ui/dataset-explorer/frontend/node_modules/playwright-core/bin/reinstall_msedge_dev_mac.sh
mediumRemote Payloadmatched "curl " · nl_code-0.7.0/ui/dataset-explorer/frontend/node_modules/playwright-core/bin/reinstall_msedge_stable_mac.sh
mediumCredential file accessmatched ".npmrc" · nl_code-0.7.0/ui/dataset-explorer/frontend/node_modules/global-prefix/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.7.0High risk602026-06-09

Block this in CI

PkgRadar gates nl-code (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi nl-code==0.7.0