PkgRadar

PyPI · pypi.org

openosint

Remote Payload: matched "curl "

Why PkgRadar flagged 2.17.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · openosint-2.17.0/openosint/agent.py
mediumRemote Payloadmatched "curl " · openosint-2.17.0/openosint/cli.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.21.0Low risk02026-06-14
2.20.0Low risk02026-06-14
2.19.1Low risk02026-06-09
2.19.0Low risk02026-06-05
2.18.0Low risk02026-05-30
2.17.0Review392026-05-27
2.16.2Review392026-05-26
2.16.1Review392026-05-26
2.16.0Review392026-05-26

Block this in CI

PkgRadar gates openosint (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi openosint==2.17.0