Go modules · proxy.golang.org
github.com/Sigstore/Protobuf-specs
Remote Payload: matched "cUrl "
Why PkgRadar flagged v0.4.0
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "cUrl " · github.com/sigstore/[email protected]/gen/pb-go/trustroot/v1/sigstore_trustroot.pb.go |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v0.1.0 | Low risk | 0 | 2026-06-18 |
v0.3.0-beta.2 | Low risk | 0 | 2026-06-18 |
v0.4.2 | Low risk | 0 | 2026-06-18 |
v0.4.1 | Low risk | 0 | 2026-06-18 |
v0.5.1 | Low risk | 0 | 2026-06-18 |
v0.5.2-0.20260615115027-c43a10eb8e5f | Low risk | 0 | 2026-06-18 |
v0.4.0 | Review | 12 | 2026-06-18 |
Block this in CI
pkgradar gate --ecosystem go github.com/Sigstore/[email protected]