PkgRadar

Go modules · proxy.golang.org

code.forgejo.org/forgejo/runner/v12

Remote Payload: matched "curl "

Why PkgRadar flagged v12.11.2-0.20260612201102-1f6b35ba1cec

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · code.forgejo.org/forgejo/runner/[email protected]/act/runner/run_context.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v12.11.2-0.20260612201102-1f6b35ba1cecReview122026-06-13
v12.11.1Review122026-06-13
v12.10.3-0.20260609002754-83e5c9bdd5dfReview122026-06-10
v12.10.3-0.20260608202831-b3f69985d7d0Review122026-06-09
v12.10.3-0.20260606025711-c40664f26f3eReview122026-06-07
v12.10.3-0.20260606001203-9c8f6a24c1a9Review122026-06-07
v12.10.3-0.20260605063451-9b5a5db796dcReview122026-06-06
v12.10.3-0.20260605005411-c0df61e2d140Review122026-06-06
v12.10.3-0.20260604135754-92331cc3782eReview122026-06-05
v12.10.3-0.20260604034630-90290879e883Review122026-06-05
v12.10.3-0.20260601233137-a632f126e6a0Review122026-06-02
v12.10.3-0.20260601215031-c4e160da2a58Review122026-06-02
v12.10.3-0.20260601022016-4439322c7da4Review122026-06-02
v12.10.3-0.20260531020603-34eeb380be18Review122026-06-01
v12.10.3-0.20260528020437-db54e1688fe6Review122026-05-30
v12.10.3-0.20260529013109-b1b45cb60568Review122026-05-30
v12.10.3-0.20260528231103-cbec40b5d904Review122026-05-29
v12.10.3-0.20260528164449-e247b92bc370Review122026-05-29

Block this in CI

PkgRadar gates code.forgejo.org/forgejo/runner/v12 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go code.forgejo.org/forgejo/runner/[email protected]