PkgRadar

Go modules · proxy.golang.org

github.com/VMWARE-TANZU/pinniped

Remote Payload: matched "curl "

Why PkgRadar flagged v0.4.2

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/vmware-tanzu/[email protected]/go.sum

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.22.0Low risk02026-06-19
v0.33.0Low risk02026-06-19
v0.29.0Low risk02026-06-19
v0.30.0Low risk02026-06-19
v0.39.0Low risk02026-06-19
v0.38.0Low risk02026-06-19
v0.2.0Low risk02026-06-19
v0.4.2Review122026-06-19
v0.16.0Review122026-06-19
v0.46.1-0.20260511182720-4220d9c172adLow risk02026-06-19
v0.46.0Low risk02026-06-19
v0.12.1Review122026-06-19
v0.6.0Review122026-06-19
v0.11.0Review122026-06-19

Block this in CI

PkgRadar gates github.com/VMWARE-TANZU/pinniped (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/VMWARE-TANZU/[email protected]