PkgRadar

Go modules · proxy.golang.org

code.forgejo.org/ofhansen/runner/v12

Remote Payload: matched "curl "

Why PkgRadar flagged v12.8.2

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · code.forgejo.org/ofhansen/runner/[email protected]/act/runner/run_context.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v12.8.2Review122026-06-18
v12.10.2Review122026-06-18
v12.3.0Review122026-06-18
v12.1.1Review122026-06-18
v12.2.0Review122026-06-18
v12.6.1Review122026-06-18
v12.6.3Review122026-06-18
v12.3.1Review122026-06-18
v12.7.3Review122026-06-18
v12.1.0Review122026-06-18
v12.11.0Review122026-06-18
v12.5.0Review122026-06-18
v12.8.0Review122026-06-18
v12.6.0Review122026-06-18
v12.10.1Review122026-06-18
v12.7.1Review122026-06-18
v12.10.0Review122026-06-18
v12.0.1Review122026-06-18
v12.11.1Review122026-06-18
v12.11.2-0.20260617103738-2d06f934601fReview122026-06-18
v12.5.2Review122026-06-18

Block this in CI

PkgRadar gates code.forgejo.org/ofhansen/runner/v12 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go code.forgejo.org/ofhansen/runner/[email protected]