PkgRadar

Go modules · proxy.golang.org

github.com/apache/arrow-rs

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260527201641-e470187b93b1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/apache/[email protected]/dev/release/run-rat.sh
mediumRemote Payloadmatched "curl " · github.com/apache/[email protected]/dev/release/verify-release-candidate.sh
mediumRemote Payloadmatched "wget " · github.com/apache/[email protected]/parquet/regen.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260616205600-78ca92d6ce0fLow risk02026-06-18
v0.0.0-20260613022309-be664614ab68Low risk02026-06-14
v0.0.0-20260613011910-11a58ac3ec70Low risk02026-06-14
v0.0.0-20260612044919-c4a831a1c81bLow risk02026-06-13
v0.0.0-20260611211742-1ba5d486a45bLow risk02026-06-12
v0.0.0-20260611163815-826b808b2792Low risk02026-06-12
v0.0.0-20260610185451-301eb26bb923Low risk02026-06-11
v0.0.0-20260610183533-e106c1534095Low risk02026-06-11
v0.0.0-20260610113045-c3e0684179d2Low risk02026-06-11
v0.0.0-20260610063118-d4c1b44e2b4dLow risk02026-06-11
v0.0.0-20260609175021-481223f87509Low risk02026-06-10
v0.0.0-20260605185318-f01ff3d47bb9Low risk02026-06-07
v0.0.0-20260605100625-e5e66fa05ce9Low risk02026-06-06
v0.0.0-20260604205659-9f96a8f5c3f4Low risk02026-06-05
v0.0.0-20260603201725-2a1d40d35c3dLow risk02026-06-05
v0.0.0-20260603134553-97f4b1460cd3Low risk02026-06-04
v0.0.0-20260603003616-f03e1bc02863Low risk02026-06-04
v0.0.0-20260602234920-259cff297c5aLow risk02026-06-04
v0.0.0-20260602210937-cfc2b88d1d4eLow risk02026-06-03
v0.0.0-20260602145553-57eeb266af09Low risk02026-06-03
v0.0.0-20260601143235-38778f011072Low risk02026-06-02
v0.0.0-20260531031811-511ad068ae2bLow risk02026-06-01
v0.0.0-20260527201641-e470187b93b1Review412026-05-29

Block this in CI

PkgRadar gates github.com/apache/arrow-rs (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/apache/[email protected]