PkgRadar

PyPI · pypi.org

squidient

Remote Payload: matched "wget "

Why PkgRadar flagged 3.0.10

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · squidient-3.0.10/src/squidient/data/terraform/aws-ec2-t3.small/t3.small/cloud-init-slurm-fedora.sh
mediumRemote Payloadmatched "wget " · squidient-3.0.10/src/squidient/data/terraform/aws-ec2-t3.small-x2/t3.small/cloud-init-slurm-fedora.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
3.0.10Review162026-06-14
3.0.9Review162026-06-13
3.0.8Review242026-06-12
3.0.7Review242026-06-10
3.0.6Review242026-06-09
3.0.4Review242026-06-08
3.0.3Review242026-06-08
3.0.2Review242026-06-08
3.0.1Review242026-06-05
3.0.0Review242026-06-03
2.5.1Review242026-05-30
2.5.0Review242026-05-30
2.7.0Review242026-05-30
2.6.1Review242026-05-29
2.6.0Review242026-05-29
2.5.2Review242026-05-28

Block this in CI

PkgRadar gates squidient (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi squidient==3.0.10