PkgRadar

Go modules · proxy.golang.org

github.com/SUNET/vc

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.5.14

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/sunet/[email protected]/internal/apigw/apiv1/handlers_oauth.go
mediumRemote Payloadmatched "cURL " · github.com/sunet/[email protected]/internal/apigw/auth_providers/samlsp/mdq.go
mediumRemote Payloadmatched "cURL\n\t" · github.com/sunet/[email protected]/internal/verifier/apiv1/handler_oidc.go
mediumRemote Payloadmatched "cURL " · github.com/sunet/[email protected]/pkg/configuration/config.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.5.14High risk482026-06-04
v0.5.14-0.20260602110226-9e78a2e2e9abHigh risk482026-06-04
v0.5.15High risk482026-06-04
v0.5.14-0.20260601142111-b58a09214980High risk482026-06-03
v0.5.12High risk362026-06-03
v0.5.13High risk362026-06-03

Block this in CI

PkgRadar gates github.com/SUNET/vc (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/SUNET/[email protected]