PkgRadar

PyPI · pypi.org

tentacletk

Remote Payload: matched "Curl "

Why PkgRadar flagged 0.12.5

SeveritySignalEvidence
mediumRemote Payloadmatched "Curl " · tentacle/slots/maya/nurbs.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.12.30Low risk02026-06-11
0.12.27Low risk02026-06-10
0.12.25Low risk02026-06-10
0.12.22Low risk02026-06-09
0.12.20Low risk02026-06-08
0.12.17Low risk02026-06-07
0.12.14Low risk02026-06-05
0.12.11Low risk02026-06-04
0.12.8Low risk02026-06-04
0.12.5Review62026-05-27
0.12.4Review62026-05-27
0.12.3Review62026-05-27
0.12.0Review62026-05-27
0.11.99Review62026-05-27

Block this in CI

PkgRadar gates tentacletk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi tentacletk==0.12.5