PkgRadar

Go modules · proxy.golang.org

github.com/FootprintAI/Containarium

Remote Payload: matched "wget "

Why PkgRadar flagged v0.19.1

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · github.com/footprintai/[email protected]/internal/app/buildpack/static.go
mediumRemote Payloadmatched "curl " · github.com/footprintai/[email protected]/internal/cmd/expose_port.go
mediumRemote Payloadmatched "cURL " · github.com/footprintai/[email protected]/internal/cmd/hosting_providers.go
mediumRemote Payloadmatched "curl " · github.com/footprintai/[email protected]/internal/cmd/hosting_setup.go
mediumRemote Payloadmatched "curl " · github.com/footprintai/[email protected]/internal/cmd/login.go
mediumRemote Payloadmatched "curl " · github.com/footprintai/[email protected]/internal/cmd/token.go
mediumRemote Payloadmatched "curl " · github.com/footprintai/[email protected]/internal/mcp/tools.go
mediumRemote Payloadmatched "github.com/projectdiscovery/nuclei/releases/download" · github.com/footprintai/[email protected]/internal/pentest/installer.go
mediumRemote Payloadmatched "github.com/open-telemetry/opentelemetry-collector-releases/releases/download" · github.com/footprintai/[email protected]/internal/server/core_otel_collector.go
mediumRemote Payloadmatched "wget " · github.com/footprintai/[email protected]/internal/server/core_services.go
mediumRemote Payloadmatched "github.com/zaproxy/zaproxy/releases/download" · github.com/footprintai/[email protected]/internal/zap/installer.go
mediumRemote Payloadmatched "curl " · github.com/footprintai/[email protected]/pkg/core/coresys/manager.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.19.1High risk1652026-05-30
v0.19.2High risk1652026-05-30
v0.18.1High risk1502026-05-30
v0.19.0High risk1652026-05-30

Block this in CI

PkgRadar gates github.com/FootprintAI/Containarium (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/FootprintAI/[email protected]