PkgRadar

Go modules · proxy.golang.org

code.cloudfoundry.org/cli/v9

Remote Payload: matched "Curl "

Why PkgRadar flagged v9.0.0-20260616040035-10803a1df1a1

SeveritySignalEvidence
mediumRemote Payloadmatched "Curl " · code.cloudfoundry.org/cli/[email protected]/cf/commands/curl.go
mediumRemote Payloadmatched "Curl " · code.cloudfoundry.org/cli/[email protected]/command/common/command_list_v7.go
mediumRemote Payloadmatched "curl " · code.cloudfoundry.org/cli/[email protected]/command/v7/curl_command.go
mediumRemote Payloadmatched "curl " · code.cloudfoundry.org/cli/[email protected]/plugin/plugin_examples/test_rpc_server_example/test_rpc_server_example.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v9.0.0-20260616040035-10803a1df1a1High risk482026-06-17
v9.0.0-20260603045202-5ade2523aa8cHigh risk482026-06-04
v9.0.0-20260529022355-c2ab3b51844eReview482026-05-30

Block this in CI

PkgRadar gates code.cloudfoundry.org/cli/v9 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go code.cloudfoundry.org/cli/[email protected]