PkgRadar

PyPI · pypi.org

pulumi-docker-build

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 0.1.0a1779928507

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · pulumi_docker_build-0.1.0a1779928507/pulumi_docker_build/image.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.0a1781075065Low risk02026-06-10
0.1.0a1780988143Low risk02026-06-09
0.1.0a1780971352Low risk02026-06-09
0.1.0a1780936852Low risk02026-06-08
0.1.0a1780902435Low risk02026-06-08
0.1.0a1780815651Low risk02026-06-07
0.1.0a1780728210Low risk02026-06-06
0.1.0a1780642936Low risk02026-06-05
0.1.0a1780629471Low risk02026-06-05
0.1.0a1780556625Low risk02026-06-04
0.1.0a1780470420Low risk02026-06-03
0.1.0a1780122912Low risk02026-05-30
0.1.0a1780119772Low risk02026-05-30
0.1.0a1780003823Low risk02026-05-29
0.1.0a1779951427Low risk02026-05-28
0.1.0a1779928507Review132026-05-28
0.0.18Review132026-05-27
0.1.0a1779889107Review132026-05-27
0.1.0a1779865278Review132026-05-27

Block this in CI

PkgRadar gates pulumi-docker-build (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi pulumi-docker-build==0.1.0a1779928507