PkgRadar

Go modules · proxy.golang.org

github.com/aikidosec/safechain-internals

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.0.2

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/aikidosec/[email protected]/internal/platform/platform_darwin.go
mediumRemote Payloadmatched "cURL " · github.com/aikidosec/[email protected]/internal/platform/platform_darwin_debug_utils.go
mediumRemote Payloadmatched "cURL " · github.com/aikidosec/[email protected]/internal/platform/platform_windows.go
mediumRemote Payloadmatched "cURL " · github.com/aikidosec/[email protected]/internal/proxy/common.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.6.5Low risk02026-06-16
v1.6.4Low risk02026-06-13
v1.6.2-0.20260609140929-18aa4666bf23Low risk02026-06-10
v0.0.2High risk482026-06-08
v1.0.0-s3-testHigh risk482026-06-08
v1.5.12-0.20260606190703-8084d0d57a4aHigh risk532026-06-08
v1.5.11High risk482026-06-08
v1.5.11-0.20260604161001-0a2ecef8f535High risk482026-06-05
v1.5.10High risk482026-06-05
v1.5.10-0.20260604100431-cdc9406f3951High risk482026-06-05
v1.5.9High risk482026-06-05
v1.5.9-0.20260601164045-ef93ba7f89bfHigh risk482026-06-02
v1.5.7Review482026-05-29

Block this in CI

PkgRadar gates github.com/aikidosec/safechain-internals (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/aikidosec/[email protected]