PkgRadar

Go modules · proxy.golang.org

git.arvados.org/arvados.git

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.0.0-20260611155551-af950fe3ab4d

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · git.arvados.org/[email protected]/sdk/go/arvados/config.go
mediumRemote Payloadmatched "cURL " · git.arvados.org/[email protected]/sdk/go/health/aggregator.go
mediumRemote Payloadmatched "wget " · git.arvados.org/[email protected]/services/keep-web/handler.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260611155551-af950fe3ab4dHigh risk532026-06-12
v0.0.0-20260610190921-74d124387aebHigh risk532026-06-11
v0.0.0-20260605164553-42241ca3fa22High risk532026-06-09
v0.0.0-20260602153734-fa9b3106ebe8High risk532026-06-03
v0.0.0-20260527185748-f6bb87c04f87High risk532026-05-30

Block this in CI

PkgRadar gates git.arvados.org/arvados.git (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go git.arvados.org/[email protected]