PkgRadar

PyPI · pypi.org

trufo-provenance

Large Native Blob: 30563112 bytes

Why PkgRadar flagged 0.1.2

SeveritySignalEvidence
mediumLarge Native Blob30563112 bytes · tfprov/c2pa_rs_bridge/libc2pa_rs_bridge.so

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.2Review152026-06-02

Block this in CI

PkgRadar gates trufo-provenance (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi trufo-provenance==0.1.2