PkgRadar

Go modules · proxy.golang.org

code.forgejo.org/aahlenst/runner/v12

Remote Payload: matched "curl "

Why PkgRadar flagged v12.0.0-20260612201102-1f6b35ba1cec

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · code.forgejo.org/aahlenst/runner/[email protected]/act/runner/run_context.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v12.0.0-20260612201102-1f6b35ba1cecReview122026-06-16
v12.0.0-20260606025711-c40664f26f3eReview122026-06-09
v12.0.0-20260607112236-bf9dbfacb0e2Review122026-06-09
v12.0.0-20260607110703-272975dc1526Review122026-06-08
v12.0.0-20260605154149-04552f18e1b7Review122026-06-06
v12.0.0-20260605150855-5bc2eb62605fReview122026-06-06
v12.0.0-20260604145826-b3c107398095Review122026-06-05
v12.0.0-20260604152654-5cc020eab5e8Review122026-06-05
v12.0.0-20260531020603-34eeb380be18Review122026-06-03
v12.0.0-20260529013109-b1b45cb60568Review122026-05-31

Block this in CI

PkgRadar gates code.forgejo.org/aahlenst/runner/v12 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go code.forgejo.org/aahlenst/runner/[email protected]