PkgRadar

Go modules · proxy.golang.org

codeberg.org/ddx/agora

Remote Payload: matched "curl "

Why PkgRadar flagged v1.3.1-0.20260531102645-259c60972401

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · codeberg.org/ddx/[email protected]/cmd/agora/commands/clone.go
mediumRemote Payloadmatched "curl " · codeberg.org/ddx/[email protected]/cmd/agora/commands/fetch.go
mediumRemote Payloadmatched "cURL " · codeberg.org/ddx/[email protected]/cmd/lei/main.go
mediumRemote Payloadmatched "cURL " · codeberg.org/ddx/[email protected]/pkg/lei/mirror.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.3.1-0.20260531102645-259c60972401High risk532026-06-01
v1.0.0High risk532026-06-01
v1.2.0High risk532026-06-01
v1.3.0High risk532026-06-01

Block this in CI

PkgRadar gates codeberg.org/ddx/agora (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go codeberg.org/ddx/[email protected]