PkgRadar

Go modules · proxy.golang.org

github.com/RealOrko/packer

Remote Payload: matched "curl "

Why PkgRadar flagged v1.3.5

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/realorko/[email protected]/builder/googlecompute/startup.go
mediumRemote Payloadmatched "curl " · github.com/realorko/[email protected]/builder/oracle/classic/pv_config.go
mediumRemote Payloadmatched "curl " · github.com/realorko/[email protected]/post-processor/googlecompute-export/startup.go
mediumRemote Payloadmatched "curl " · github.com/realorko/[email protected]/provisioner/chef-client/provisioner.go
mediumRemote Payloadmatched "curl " · github.com/realorko/[email protected]/provisioner/chef-solo/provisioner.go
mediumRemote Payloadmatched "curl " · github.com/realorko/[email protected]/provisioner/converge/provisioner.go
mediumRemote Payloadmatched "curl " · github.com/realorko/[email protected]/provisioner/salt-masterless/provisioner.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.3.5High risk1082026-06-08
v0.9.0-rc2High risk442026-06-08
v1.4.6-0.20191112230819-58a7448c86cdHigh risk1182026-06-08
v0.4.1High risk482026-06-08
v0.3.9High risk482026-06-08
v1.4.0High risk1082026-06-08
v0.1.1Review242026-06-08
v0.11.0High risk952026-06-08
v1.3.0High risk1112026-06-08
v1.2.2High risk1112026-06-08
v1.2.0High risk1022026-06-08
v0.12.3High risk952026-06-08
v0.2.1Review242026-06-08
v1.1.2High risk1022026-06-08
v1.1.0High risk1022026-06-08
v1.0.2High risk932026-06-08
v1.4.5High risk1182026-06-08
v1.4.4High risk1082026-06-08
v1.0.1High risk932026-06-08
v0.1.5Review292026-06-08
v1.0.0-rc2High risk952026-06-08
v1.0.0-rc3High risk952026-06-08
v1.0.0-rc1High risk952026-06-08
v0.8.6High risk362026-06-08
v0.1.0Review242026-06-08
v0.10.1High risk492026-06-08
v0.2.0Review242026-06-08
v0.3.1High risk362026-06-08
v0.3.10High risk482026-06-08
v0.3.2High risk362026-06-08
v0.7.1High risk602026-06-08
v0.8.2High risk362026-06-08
v1.0.4High risk1022026-06-08
v1.2.1High risk1022026-06-08
v1.2.4High risk1112026-06-08
v1.3.2High risk1082026-06-08
v0.2.3High risk362026-06-08
v0.1.2Review242026-06-08
v1.1.3High risk1022026-06-08
v1.2.5High risk1112026-06-08
v0.8.5High risk362026-06-08
v0.4.0High risk482026-06-08
v0.9.0High risk442026-06-08
v1.4.1High risk1082026-06-08
v0.5.1High risk482026-06-08
v0.3.3High risk362026-06-08
v1.4.3High risk1082026-06-08
v1.3.4High risk1082026-06-08
v1.1.1High risk1022026-06-08
v1.3.3High risk1082026-06-08
v0.10.2High risk492026-06-08
v0.12.2High risk952026-06-08
v1.3.1High risk1112026-06-08
v0.12.0High risk952026-06-08
v0.8.3High risk362026-06-08
v0.3.5High risk482026-06-08
v1.0.3High risk992026-06-08
v0.3.7High risk482026-06-08
v0.7.2High risk602026-06-08
v0.8.0High risk362026-06-08
v1.4.2High risk1082026-06-08
v0.6.1High risk602026-06-08
v0.3.6High risk482026-06-08
v1.0.0High risk952026-06-08
v0.3.4High risk362026-06-08
v1.2.3High risk1112026-06-08
v0.10.0High risk492026-06-08
v0.5.0High risk482026-06-08
v0.5.2High risk482026-06-08
v0.6.0High risk602026-06-08
v0.3.0High risk362026-06-08
v0.3.11High risk482026-06-08
v0.8.1High risk362026-06-08
v0.7.0High risk602026-06-08
v0.7.5High risk602026-06-08
v0.3.8High risk482026-06-08
v0.1.3Review242026-06-08
v0.12.1High risk932026-06-08
v0.1.4Review292026-06-08
v0.2.2High risk362026-06-08

Block this in CI

PkgRadar gates github.com/RealOrko/packer (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/RealOrko/[email protected]