PkgRadar

Go modules · proxy.golang.org

github.com/ViniciosLugli/DeepSeek-Code-Whale

Remote Payload: matched "curl "

Why PkgRadar flagged v0.1.31

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/vinicioslugli/[email protected]/internal/policy/policy_defaults.go
mediumRemote Payloadmatched "iwr " · github.com/vinicioslugli/[email protected]/internal/updatecheck/updatecheck.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/vinicioslugli/[email protected]/internal/webfetch/webfetch.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.1.6Low risk02026-06-02
v0.1.31High risk362026-06-02
v0.1.11Low risk02026-06-02
v0.1.32High risk362026-06-02
v0.1.25Review242026-06-02
v0.1.22Review242026-06-02
v0.1.9Low risk02026-06-02
v0.1.3Low risk02026-06-02
v0.1.2Low risk02026-06-02
v0.1.0Low risk02026-06-02
v0.1.23Review242026-06-02
v0.1.26Review242026-06-02
v0.1.17Review242026-06-02
v0.1.16Low risk02026-06-02
v0.1.29High risk362026-06-02
v0.1.28High risk362026-06-02
v0.1.33High risk362026-06-02
v0.1.34-0.20260601232739-c38158c7a27aHigh risk362026-06-02

Block this in CI

PkgRadar gates github.com/ViniciosLugli/DeepSeek-Code-Whale (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/ViniciosLugli/[email protected]