PkgRadar

Go modules · proxy.golang.org

github.com/alessandro-bitetto/chaindora

Known Indicator Filename: github.com/alessandro-bitetto/[email protected]/testdata/fake-home/somerepo/.github/workflows/shai-hulud-workflow.yml

Why PkgRadar flagged v0.16.1

SeveritySignalEvidence
highKnown Indicator Filenamegithub.com/alessandro-bitetto/[email protected]/testdata/fake-home/somerepo/.github/workflows/shai-hulud-workflow.yml · github.com/alessandro-bitetto/[email protected]/testdata/fake-home/somerepo/.github/workflows/shai-hulud-workflow.yml
highKnown Indicator Filenamegithub.com/alessandro-bitetto/[email protected]/testdata/ghactions/.github/workflows/shai-hulud-workflow.yml · github.com/alessandro-bitetto/[email protected]/testdata/ghactions/.github/workflows/shai-hulud-workflow.yml
mediumRemote Payloadmatched "curl " · github.com/alessandro-bitetto/[email protected]/internal/detectors/heuristic/cishell.go
mediumRemote Payloadmatched "invoke-webrequest" · github.com/alessandro-bitetto/[email protected]/internal/detectors/hostforensics/powershell.go
mediumRemote Payloadmatched "curl " · github.com/alessandro-bitetto/[email protected]/internal/detectors/hostforensics/shellrc.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/alessandro-bitetto/[email protected]/internal/detectors/trustdrift/trustdrift.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/alessandro-bitetto/[email protected]/internal/findings/sarif.go
mediumRemote Payloadmatched "cURL " · github.com/alessandro-bitetto/[email protected]/internal/registries/maven.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.16.1High risk1852026-06-12

Block this in CI

PkgRadar gates github.com/alessandro-bitetto/chaindora (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/alessandro-bitetto/[email protected]