PkgRadar

Go modules · proxy.golang.org

cos.googlesource.com/cos/tools.git

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.0.0-20260603222957-5d7b1afb431c

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · cos.googlesource.com/cos/[email protected]/src/cmd/cos_customizer/install_packages.go
mediumRemote Payloadmatched "cURL " · cos.googlesource.com/cos/[email protected]/src/pkg/provisioner/install_packages_step.go
mediumRemote Payloadmatched "cURL " · cos.googlesource.com/cos/[email protected]/src/pkg/tools/sbomutil/sbomutil.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260603222957-5d7b1afb431cHigh risk412026-06-04

Block this in CI

PkgRadar gates cos.googlesource.com/cos/tools.git (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go cos.googlesource.com/cos/[email protected]