PkgRadar

PyPI · pypi.org

tollbooth-dpyc

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 0.38.0

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · tollbooth_dpyc-0.38.0/src/tollbooth/registry.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.44.15Low risk02026-06-11
0.44.14Low risk02026-06-11
0.44.13Low risk02026-06-11
0.44.12Low risk02026-06-11
0.44.11Low risk02026-06-11
0.44.10Low risk02026-06-11
0.44.9Low risk02026-06-11
0.44.8Low risk02026-06-11
0.44.7Low risk02026-06-11
0.44.6Low risk02026-06-11
0.44.5Low risk02026-06-11
0.44.4Low risk02026-06-11
0.44.3Low risk02026-06-10
0.44.2Low risk02026-06-10
0.44.1Low risk02026-06-07
0.44.0Low risk02026-06-07
0.43.0Low risk02026-06-07
0.42.0Low risk02026-06-04
0.41.1Low risk02026-06-03
0.41.0Low risk02026-06-03
0.40.0Low risk02026-06-02
0.39.0Low risk02026-05-31
0.38.0Review202026-05-27

Block this in CI

PkgRadar gates tollbooth-dpyc (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi tollbooth-dpyc==0.38.0