PkgRadar

Go modules · proxy.golang.org

gitee.com/hexug/go-tools

Remote Payload: matched "cUrl "

Why PkgRadar flagged v1.3.12-0.20260611165705-9a1f70837249

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · gitee.com/hexug/[email protected]/msgbot/dingtalk/out_msg_model.go
mediumRemote Payloadmatched "cUrl " · gitee.com/hexug/[email protected]/msgbot/dingtalk/sender_link.go
mediumRemote Payloadmatched "CURL " · gitee.com/hexug/[email protected]/msgbot/feishu/out_msg_model.go
mediumRemote Payloadmatched "cURL " · gitee.com/hexug/[email protected]/msgbot/wecom/out_msg_model.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.3.12-0.20260611165705-9a1f70837249High risk482026-06-13
v1.3.12High risk482026-06-13
v1.3.11High risk482026-06-10
v1.3.10High risk482026-06-05
v1.3.9High risk482026-06-04
v1.3.8High risk482026-06-03
v1.3.7High risk482026-06-02
v1.3.7-0.20260601033356-1c8b97ad4eccHigh risk482026-06-02
v1.3.6High risk482026-06-02
v1.3.4-0.20260528111337-748c2f3e440cHigh risk482026-05-30
v1.3.3High risk482026-05-30
v1.3.5Review482026-05-29
v1.3.4Review482026-05-29
v1.3.1Review482026-05-29
v1.3.0Review482026-05-29

Block this in CI

PkgRadar gates gitee.com/hexug/go-tools (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go gitee.com/hexug/[email protected]