PkgRadar

Go modules · proxy.golang.org

github.com/GoogleCloudPlatform/buildpacks

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260605133825-c202748d06f3

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/googlecloudplatform/[email protected]/cmd/cpp/functions_framework/lib/lib.go
mediumRemote Payloadmatched "github.com/graalvm/graalvm-ce-builds/releases/download" · github.com/googlecloudplatform/[email protected]/cmd/java/graalvm/lib/lib.go
mediumRemote Payloadmatched "curl " · github.com/googlecloudplatform/[email protected]/cmd/java/gradle/lib/lib.go
mediumRemote Payloadmatched "curl " · github.com/googlecloudplatform/[email protected]/cmd/java/maven/lib/lib.go
mediumRemote Payloadmatched "cURL " · github.com/googlecloudplatform/[email protected]/pkg/devmode/devmode.go
mediumRemote Payloadmatched "github.com/pnpm/pnpm/releases/download" · github.com/googlecloudplatform/[email protected]/pkg/nodejs/pnpm.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260605133825-c202748d06f3High risk772026-06-06
v0.0.0-20260603201606-fb7a183f6203High risk772026-06-05
v0.0.0-20260602190356-232250adb218High risk772026-06-03

Block this in CI

PkgRadar gates github.com/GoogleCloudPlatform/buildpacks (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/GoogleCloudPlatform/[email protected]