PkgRadar

PyPI · pypi.org

pyravelry

Remote Payload: matched "curl "

Why PkgRadar flagged 0.0.10

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · pyravelry-0.0.10/.devcontainer/postCreateCommand.sh
mediumRemote Payloadmatched "curl " · pyravelry-0.0.10/.github/workflows/validate-codecov-config.yml

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.10Review242026-05-27

Block this in CI

PkgRadar gates pyravelry (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi pyravelry==0.0.10