PkgRadar

PyPI · pypi.org

tko

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 9.17.9

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · tko-9.17.9/src/tko/config/check_version.py
mediumRemote Payloadmatched "raw.githubusercontent.com" · tko-9.17.9/src/tko/feno/github_url_structure.py
mediumRemote Payloadmatched "raw.githubusercontent.com" · tko-9.17.9/src/tko/feno/link_rebase.py
mediumRemote Payloadmatched "raw.githubusercontent.com" · tko-9.17.9/src/tko/feno/remote_md.py

Scanned versions

VersionVerdictScoreScanned (UTC)
9.21.0Low risk02026-06-12
9.20.0Low risk02026-06-09
9.19.0Low risk02026-06-03
9.18.0Low risk02026-06-03
9.17.4Low risk02026-05-30
9.17.9Review242026-05-27
9.17.8Review242026-05-27
9.17.7Review242026-05-27
9.17.6Review242026-05-27
9.17.5Review242026-05-27
9.17.4.dev1Review242026-05-27

Block this in CI

PkgRadar gates tko (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi tko==9.17.9