Go modules · proxy.golang.org
chainguard.dev/apko
Remote Payload: matched "curl "
Why PkgRadar flagged v1.2.15-0.20260527181455-74e64086fae7
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "curl " · chainguard.dev/[email protected]/pkg/sbom/generator/spdx/testdata/apk_sboms/_generate.sh |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v1.2.18-0.20260616051512-ebd9255d9199 | Low risk | 0 | 2026-06-17 |
v1.2.17-0.20260613010730-301fd0d625c7 | Low risk | 0 | 2026-06-14 |
v1.2.17-0.20260612182453-ef578c30be29 | Low risk | 0 | 2026-06-13 |
v1.2.17-0.20260612124220-6b57924d877d | Low risk | 0 | 2026-06-13 |
v1.2.16 | Low risk | 0 | 2026-06-09 |
v1.2.16-0.20260604050125-8bf905593d45 | Low risk | 0 | 2026-06-05 |
v1.2.15 | Low risk | 0 | 2026-06-02 |
v1.2.15-0.20260527181455-74e64086fae7 | Review | 12 | 2026-05-29 |
Block this in CI
pkgradar gate --ecosystem go chainguard.dev/[email protected]