PkgRadar

PyPI · pypi.org

taxcalc

Remote Payload: matched "curl\n "

Why PkgRadar flagged 6.6.1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl\n " · taxcalc-6.6.1/conda.recipe/meta.yaml
mediumRemote Payloadmatched "curl\n" · taxcalc-6.6.1/environment.yml
mediumRemote Payloadmatched "raw.githubusercontent.com" · taxcalc-6.6.1/taxcalc/parameters.py

Scanned versions

VersionVerdictScoreScanned (UTC)
6.6.2Low risk02026-06-05
6.6.1Review212026-05-28

Block this in CI

PkgRadar gates taxcalc (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi taxcalc==6.6.1