PkgRadar

Go modules · proxy.golang.org

github.com/alecmuffett/real-world-onion-sites

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260528033136-601fbea0a853

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/alecmuffett/[email protected]/get-fresh-csv.sh
mediumRemote Payloadmatched "curl " · github.com/alecmuffett/[email protected]/manual-check.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260612034237-b8a192c09703Low risk02026-06-13
v0.0.0-20260611033312-d05d922b975bLow risk02026-06-12
v0.0.0-20260610033208-d662b485348bLow risk02026-06-11
v0.0.0-20260609033434-bc5ba5dc9c7fLow risk02026-06-10
v0.0.0-20260608033154-b267cb4b1287Low risk02026-06-09
v0.0.0-20260605033313-2b96523ac8f9Low risk02026-06-06
v0.0.0-20260604033114-8562fa3d24f9Low risk02026-06-05
v0.0.0-20260603033303-3343f42baa52Low risk02026-06-04
v0.0.0-20260602033331-a7a6d62b8d0fLow risk02026-06-03
v0.0.0-20260601033243-2878eb0369edLow risk02026-06-02
v0.0.0-20260531033738-2019c0529733Low risk02026-06-01
v0.0.0-20260530033248-9516a57da468Low risk02026-05-31
v0.0.0-20260529033219-611d3334473aLow risk02026-05-30
v0.0.0-20260528033136-601fbea0a853Review242026-05-29

Block this in CI

PkgRadar gates github.com/alecmuffett/real-world-onion-sites (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/alecmuffett/[email protected]