PkgRadar

PyPI · pypi.org

xpander-sdk

Remote Payload: matched "Curl "

Why PkgRadar flagged 2.0.332

SeveritySignalEvidence
mediumRemote Payloadmatched "Curl " · xpander_sdk-2.0.332/src/xpander_sdk/modules/agents/models/agent.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.357Low risk02026-06-17
2.0.356Low risk02026-06-17
2.0.355Low risk02026-06-17
2.0.354Low risk02026-06-17
2.0.353Low risk02026-06-15
2.0.352Low risk02026-06-14
2.0.351Low risk02026-06-14
2.0.350Low risk02026-06-14
2.0.349Low risk02026-06-11
2.0.348Low risk02026-06-11
2.0.347Low risk02026-06-08
2.0.346Low risk02026-06-07
2.0.345Low risk02026-06-07
2.0.344Low risk02026-06-07
2.0.343Low risk02026-06-03
2.0.342Low risk02026-06-02
2.0.341Low risk02026-06-02
2.0.340Low risk02026-06-01
2.0.339Low risk02026-06-01
2.0.338Low risk02026-06-01
2.0.337Low risk02026-05-31
2.0.336Low risk02026-05-31
2.0.335Low risk02026-05-31
2.0.334Low risk02026-05-28
2.0.333Low risk02026-05-28
2.0.332Review62026-05-27
2.0.331Review62026-05-27
2.0.330Review62026-05-27

Block this in CI

PkgRadar gates xpander-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi xpander-sdk==2.0.332