PkgRadar

PyPI · pypi.org

observal-cli

Remote Payload: matched "curl "

Why PkgRadar flagged 1.6.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · observal_cli-1.6.0/infra/terraform/deploy.sh
mediumRemote Payloadmatched "curl " · observal_cli-1.6.0/infra/terraform/aws/deploy.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.6.0Review372026-06-13
1.5.0Review372026-06-09
1.4.4Review372026-06-01
1.4.3Review302026-05-31
1.4.2Review352026-05-31
1.4.1Review232026-05-31
1.4.0Review232026-05-31
1.3.1Review232026-05-30
1.2.1Review182026-05-30
1.2.0Review182026-05-30
1.3.0Review232026-05-29

Block this in CI

PkgRadar gates observal-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi observal-cli==1.6.0