PkgRadar

Go modules · proxy.golang.org

github.com/Redpanda-data/connect/v4

Remote Payload: matched "github.com/build-trust/ockam/releases/download"

Why PkgRadar flagged v4.96.2-0.20260613230638-6a3627b34e03

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/build-trust/ockam/releases/download" · github.com/redpanda-data/connect/[email protected]/internal/impl/ockam/command.go
mediumRemote Payloadmatched "github.com/ollama/ollama/releases/download" · github.com/redpanda-data/connect/[email protected]/internal/impl/ollama/subprocess_unix.go
mediumRemote Payloadmatched "cURL " · github.com/redpanda-data/connect/[email protected]/internal/impl/otlp/input_http.go
mediumRemote Payloadmatched "cURL " · github.com/redpanda-data/connect/[email protected]/internal/impl/redpanda/migrator/migrator_schema_registry.go
mediumRemote Payloadmatched "curl " · github.com/redpanda-data/connect/[email protected]/internal/impl/snowflake/output_snowflake_put.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v4.96.2-0.20260613230638-6a3627b34e03High risk832026-06-16
v4.64.0High risk412026-06-16
v4.96.1High risk832026-06-16

Block this in CI

PkgRadar gates github.com/Redpanda-data/connect/v4 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/Redpanda-data/connect/[email protected]
github.com/Redpanda-data/connect/v4 — Go modules security scan | PkgRadar