PkgRadar

Go modules · proxy.golang.org

github.com/CircleCI-Public/circleci-cli

Remote Payload: matched "curl "

Why PkgRadar flagged v0.1.36203-0.20260602212011-e5e2ee13100b

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/circleci-public/[email protected]/cmd/init.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.0.40487-preLow risk02026-06-17
v1.0.40468-preLow risk02026-06-17
v1.0.40357-pre.0.20260616151327-87c223b678b2Low risk02026-06-17
v1.0.40332-preLow risk02026-06-17
v1.0.40316-preLow risk02026-06-17
v1.0.40295-pre.0.20260616131144-a63a77e116b0Low risk02026-06-17
v1.0.40222-preLow risk02026-06-17
v1.0.40118-preLow risk02026-06-17
v1.0.40111-preLow risk02026-06-17
v1.0.40149-preLow risk02026-06-17
v1.0.40099-preLow risk02026-06-17
v1.0.40156-pre.0.20260616095653-7ff725c7a2faLow risk02026-06-17
v1.0.40156-preLow risk02026-06-17
v1.0.39977-preLow risk02026-06-16
v1.0.39919-preLow risk02026-06-13
v1.0.39879-preLow risk02026-06-13
v1.0.39867-preLow risk02026-06-12
v1.0.39856-preLow risk02026-06-12
v1.0.39791-preLow risk02026-06-12
v1.0.39688-preLow risk02026-06-12
v1.0.39559-preLow risk02026-06-11
v1.0.39577-preLow risk02026-06-11
v1.0.39535-preLow risk02026-06-11
v1.0.39497-preLow risk02026-06-11
v1.0.39518-preLow risk02026-06-11
v1.0.39485-preLow risk02026-06-11
v1.0.39547-preLow risk02026-06-11
v1.0.39463-preLow risk02026-06-11
v1.0.39390-preLow risk02026-06-11
v1.0.39428-preLow risk02026-06-11
v1.0.39407-preLow risk02026-06-11
v1.0.39378-preLow risk02026-06-10
v1.0.39369-preLow risk02026-06-10
v1.0.39377-preLow risk02026-06-10
v1.0.39362-preLow risk02026-06-10
v1.0.39208-preLow risk02026-06-09
v1.0.39179-preLow risk02026-06-09
v1.0.39036-preLow risk02026-06-09
v1.0.39060-preLow risk02026-06-09
v1.0.39003-preLow risk02026-06-09
v1.0.39054-preLow risk02026-06-09
v1.0.39030-preLow risk02026-06-09
v1.0.38875-preLow risk02026-06-07
v1.0.38789-preLow risk02026-06-05
v1.0.38778-preLow risk02026-06-05
v1.0.38823-preLow risk02026-06-05
v1.0.38812-pre.0.20260604163208-a00b37c8b6b8Low risk02026-06-05
v1.0.38812-preLow risk02026-06-05
v1.0.38746-preLow risk02026-06-05
v1.0.38733-preLow risk02026-06-05
v1.0.38722-preLow risk02026-06-05
v1.0.38709-preLow risk02026-06-04
v1.0.38659-preLow risk02026-06-04
v1.0.38625-preLow risk02026-06-04
v1.0.38603-preLow risk02026-06-04
v1.0.38604-preLow risk02026-06-04
v0.1.36203-0.20260602212011-e5e2ee13100bReview172026-06-04
v1.0.38561-preLow risk02026-06-04
v1.0.38550-preLow risk02026-06-04
v1.0.38437-preLow risk02026-06-03
v1.0.38418-preLow risk02026-06-03
v1.0.38392-preLow risk02026-06-03
v1.0.38340-preLow risk02026-06-02
v1.0.38248-preLow risk02026-06-02
v1.0.38322-preLow risk02026-06-02
v1.0.38272-preLow risk02026-06-02
v1.0.38283-preLow risk02026-06-02
v1.0.38222-preLow risk02026-05-31
v1.0.38185-preLow risk02026-05-30
v0.1.36203-0.20260526013159-63e688312754Review392026-05-29
v1.0.38116-preReview52026-05-29

Block this in CI

PkgRadar gates github.com/CircleCI-Public/circleci-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/CircleCI-Public/[email protected]