PkgRadar

PyPI · pypi.org

silly-kicks

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 3.23.0

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · silly_kicks-3.23.0/scripts/build_worldcup_fixture.py

Scanned versions

VersionVerdictScoreScanned (UTC)
4.26.0Low risk02026-06-13
4.25.0Low risk02026-06-11
4.24.0Low risk02026-06-11
4.23.0Low risk02026-06-11
4.22.2Low risk02026-06-11
4.22.1Low risk02026-06-11
4.22.0Low risk02026-06-10
4.21.4Low risk02026-06-10
4.21.3Low risk02026-06-10
4.21.2Low risk02026-06-10
4.21.1Low risk02026-06-09
4.21.0Low risk02026-06-09
4.20.1Low risk02026-06-09
4.20.0Low risk02026-06-08
4.19.2Low risk02026-06-08
4.19.1Low risk02026-06-08
4.19.0Low risk02026-06-08
4.18.0Low risk02026-06-08
4.17.0Low risk02026-06-08
4.16.1Low risk02026-06-07
4.16.0Low risk02026-06-07
4.15.0Low risk02026-06-07
4.14.0Low risk02026-06-06
4.13.0Low risk02026-06-04
4.12.2Low risk02026-06-04
4.12.1Low risk02026-06-04
4.12.0Low risk02026-06-04
4.11.0Low risk02026-06-03
4.10.0Low risk02026-06-03
3.23.0Review122026-05-27
3.22.2Review122026-05-27
3.22.1Review122026-05-27
3.22.0Review122026-05-27
3.21.0Review122026-05-27
3.20.1Review122026-05-26
3.20.0Review122026-05-26

Block this in CI

PkgRadar gates silly-kicks (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi silly-kicks==3.23.0