PkgRadar

Go modules · proxy.golang.org

github.com/Tencent/WeKnora

Remote Payload: matched "curl "

Why PkgRadar flagged v0.6.1-0.20260603042913-bbd3f6324aa8

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/tencent/[email protected]/go.sum
mediumRemote Payloadmatched "curl " · github.com/tencent/[email protected]/internal/infrastructure/web_search/duckduckgo.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.6.1-0.20260603042913-bbd3f6324aa8Review342026-06-04
v0.0.0-20260603042913-bbd3f6324aa8Review342026-06-04
v0.6.1-0.20260603001906-2ba123759882Review342026-06-04
v0.0.0-20260603001906-2ba123759882Review342026-06-04
v0.6.1-0.20260602133910-09a8607cd4b7Review342026-06-03
v0.0.0-20260602133910-09a8607cd4b7Review342026-06-03
v0.6.1-0.20260601125437-482686d17ee8Review342026-06-02
v0.0.0-20260601125437-482686d17ee8Review342026-06-02
v0.6.1-0.20260601063017-65f9018f73e9Review342026-06-02
v0.0.0-20260601063017-65f9018f73e9Review342026-06-02
v0.6.1-0.20260531074330-a4557c3a8011Review342026-06-01
v0.0.0-20260531074330-a4557c3a8011Review342026-06-01
v0.6.1-0.20260530095347-e35272161d17Review342026-05-31
v0.0.0-20260530095347-e35272161d17Review342026-05-31
v0.6.1-0.20260529170015-cea6ef0ce330Review342026-05-31
v0.0.0-20260529170015-cea6ef0ce330Review342026-05-31
v0.0.0-20260528112950-c29d36238b00Review342026-05-30
v0.6.1-0.20260528072653-4e58dd42cc77Review342026-05-30
v0.0.0-20260528072653-4e58dd42cc77Review342026-05-30
v0.6.1-0.20260528000357-ae4ec0cf0673Review342026-05-30
v0.0.0-20260528000357-ae4ec0cf0673Review342026-05-30
v0.6.1-0.20260529095201-9cb950511430Review342026-05-30
v0.0.0-20260529090342-9f139ff4d89eReview342026-05-30
v0.0.0-20260529085653-2241f9579d25Review342026-05-30
v0.0.0-20260528122753-0e1282c2dac1Review342026-05-29

Block this in CI

PkgRadar gates github.com/Tencent/WeKnora (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/Tencent/[email protected]