PkgRadar

Go modules · proxy.golang.org

github.com/NVIDIA/nvcf

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260527233204-49191ea3f253

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/nvidia/[email protected]/migrations/openbao/entrypoint.sh
mediumRemote Payloadmatched "github.com/bazelbuild/bazelisk/releases/download" · github.com/nvidia/[email protected]/setup.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260616035349-f1eb12e616d0Low risk02026-06-17
v0.0.0-20260615225702-52dd21330050Low risk02026-06-16
v0.0.0-20260615221246-9ec511b36807Low risk02026-06-16
v0.0.0-20260615163806-d85fe97902b5Low risk02026-06-16
v0.0.0-20260615082340-e42fc17d2410Low risk02026-06-16
v0.0.0-20260612195734-0eb6287f001aLow risk02026-06-13
v0.0.0-20260612190709-d2a0a44bddeeLow risk02026-06-13
v0.0.0-20260612184258-62262271f9bdLow risk02026-06-13
v0.0.0-20260612164218-eaa86cca5425Low risk02026-06-13
v0.0.0-20260612141702-d508212c05b2Low risk02026-06-13
v0.0.0-20260612114711-95287a11acd6Low risk02026-06-13
v0.0.0-20260612083852-80b9e2933624Low risk02026-06-13
v0.0.0-20260611223530-07c0de7668fbLow risk02026-06-12
v0.0.0-20260611172741-1697734f20f1Low risk02026-06-12
v0.0.0-20260611165500-3ed0216bef5aLow risk02026-06-12
v0.0.0-20260611154604-810c50d7422eLow risk02026-06-12
v0.0.0-20260611051853-11be051fc110Low risk02026-06-12
v0.0.0-20260611001513-2a8a41c7887cLow risk02026-06-12
v0.0.0-20260610231045-82c44fe227b0Low risk02026-06-12
v0.0.0-20260609233324-b7cf194713ccLow risk02026-06-11
v0.0.0-20260609203347-51ff765c4662Low risk02026-06-10
v0.0.0-20260609162115-7691a8e76989Low risk02026-06-10
v0.0.0-20260609094636-c03e09d5fca6Low risk02026-06-10
v0.0.0-20260608223259-f0cc70d07e76Low risk02026-06-10
v0.0.0-20260607045420-c0de0100ed7cLow risk02026-06-09
v0.0.0-20260605201624-bb7c2a29be73Low risk02026-06-06
v0.0.0-20260604214709-a614f6cb852cLow risk02026-06-05
v0.0.0-20260604001302-0b55fda46510Low risk02026-06-05
v0.0.0-20260603225940-3f25378378abLow risk02026-06-05
v0.0.0-20260603203655-f5398273e2dfLow risk02026-06-04
v0.0.0-20260603044103-f1c916f1e3f8Low risk02026-06-04
v0.0.0-20260602205802-68cc03c635e6Low risk02026-06-04
v0.0.0-20260602114547-f4ebec05975aLow risk02026-06-03
v0.0.0-20260601212822-4e2f12a33abaLow risk02026-06-02
v0.0.0-20260601181550-4a9a8f20b88bLow risk02026-06-02
v0.0.0-20260601142643-482020ed1705Low risk02026-06-02
v0.0.0-20260529224633-701c0d67f8f6Low risk02026-05-31
v0.0.0-20260529051301-33ccea65ca01Low risk02026-05-30
v0.0.0-20260529002900-38c02a897078Low risk02026-05-30
v0.0.0-20260529000308-afd460ee12a3Low risk02026-05-30
v0.0.0-20260528225357-c46d1abdfa1bLow risk02026-05-29
v0.0.0-20260528211311-916b1e532166Low risk02026-05-29
v0.0.0-20260528192601-c440ec01adb5Low risk02026-05-29
v0.0.0-20260528183735-eaa9b9541590Low risk02026-05-29
v0.0.0-20260528052543-a04cdba0caecLow risk02026-05-29
v0.0.0-20260527233204-49191ea3f253Review242026-05-29
v0.0.0-20260528000901-09b9ac3229b0Review242026-05-29

Block this in CI

PkgRadar gates github.com/NVIDIA/nvcf (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/NVIDIA/[email protected]