PyPI · pypi.org
wandelbots-nova
Remote Payload: matched "github.com/wandelbotsgmbh/wandelbots-js-react-components/releases/download"
Why PkgRadar flagged 5.1.4a2026052720
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "github.com/wandelbotsgmbh/wandelbots-js-react-components/releases/download" · nova_rerun_bridge/helper_scripts/download_models.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
5.4.2 | Low risk | 0 | 2026-06-12 |
5.4.1 | Low risk | 0 | 2026-06-09 |
5.4.0 | Low risk | 0 | 2026-06-09 |
5.3.0 | Low risk | 0 | 2026-06-04 |
5.2.0 | Low risk | 0 | 2026-06-04 |
5.1.4 | Low risk | 0 | 2026-06-03 |
5.1.4a2026052720 | Review | 6 | 2026-05-27 |
Block this in CI
pkgradar gate --ecosystem pypi wandelbots-nova==5.1.4a2026052720