PkgRadar

PyPI · pypi.org

pumaguard

Remote Payload: matched "curl "

Why PkgRadar flagged 24.1.post53

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · pumaguard-ui/fonts/download_fonts.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
24.1.post53Review82026-06-01
24.1.post52Review82026-05-30
24.1.post50Review82026-05-30
24.1.post48Review82026-05-30
24.1.post46Review82026-05-30
24.1.post44Review82026-05-30
24.1.post42Review82026-05-30
24.1.post38Review82026-05-30
24.1.post36Review82026-05-30
24.1.post34Review82026-05-29
24.1.post32Review82026-05-29
24.1.post30Review82026-05-28
24.1.post28Review82026-05-27
24.1.post26Review82026-05-27
24.1.post24Review82026-05-26
24.1.post22Review82026-05-26

Block this in CI

PkgRadar gates pumaguard (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi pumaguard==24.1.post53