PkgRadar

PyPI · pypi.org

wood-league-worker

Remote Payload: matched "curl "

Why PkgRadar flagged 0.16.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · wood_league_worker-0.16.0/runpod/bootstrap.sh
mediumRemote Payloadmatched "raw.githubusercontent.com" · wood_league_worker-0.16.0/runpod/runpod_start.sh
mediumCredential file accessmatched "aws_access_key" · wood_league_worker-0.16.0/local_worker/cache_sync.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.16.0Review342026-05-29
0.15.1Review342026-05-27

Block this in CI

PkgRadar gates wood-league-worker (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi wood-league-worker==0.16.0