PkgRadar

PyPI · pypi.org

rlm-tools-bsl

Remote Payload: matched "curl "

Why PkgRadar flagged 1.19.2

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · rlm_tools_bsl-1.19.2/simple-install-from-pip.sh
mediumRemote Payloadmatched "curl " · rlm_tools_bsl-1.19.2/simple-install.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.19.2Review242026-06-10
1.19.1Review242026-06-10
1.19.0Review242026-06-09
1.18.0Review242026-06-07
1.17.0Review242026-06-04
1.16.0Review242026-06-03
1.15.0Review242026-05-31
1.14.0Review242026-05-30

Block this in CI

PkgRadar gates rlm-tools-bsl (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi rlm-tools-bsl==1.19.2