PkgRadar

Go modules · proxy.golang.org

github.com/BeStateless/pulumi-terraform-bridge

Remote Payload: matched "cURL "

Why PkgRadar flagged v1.6.3

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/bestateless/[email protected]/pkg/tfgen/generate.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/bestateless/[email protected]/pkg/tfgen/generate_csharp.go
mediumRemote Payloadmatched "cURL " · github.com/bestateless/[email protected]/pkg/tfgen/generate_nodejs.go
mediumRemote Payloadmatched "cURL " · github.com/bestateless/[email protected]/pkg/tfgen/generate_python.go
mediumRemote Payloadmatched "cURL " · github.com/bestateless/[email protected]/pkg/tfgen/generate_schema.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.6.3High risk602026-06-13
v1.5.2High risk602026-06-13
v1.4.0High risk502026-06-13
v1.2.0High risk482026-06-13
v1.6.1High risk602026-06-13
v1.6.6High risk602026-06-13
v1.6.2High risk602026-06-13
v1.1.0High risk482026-06-13
v1.8.4High risk482026-06-13

Block this in CI

PkgRadar gates github.com/BeStateless/pulumi-terraform-bridge (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/BeStateless/[email protected]