PkgRadar

Go modules · proxy.golang.org

github.com/apache/groovy

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260527104648-f220aa2fe7a3

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/apache/[email protected]/.muse/codenarc.sh
mediumRemote Payloadmatched "curl " · github.com/apache/[email protected]/etc/bin/download-release-artifacts.sh
mediumRemote Payloadmatched "curl " · github.com/apache/[email protected]/etc/bin/verify.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260602065805-653195f4057cLow risk02026-06-03
v0.0.0-20260602064131-25e23120efcaLow risk02026-06-03
v0.0.0-20260602020858-e93430ef8273Low risk02026-06-03
v0.0.0-20260601213019-aae4856c7c02Low risk02026-06-02
v0.0.0-20260601052225-90e292c1ead2Low risk02026-06-02
v0.0.0-20260601034937-016b0834897eLow risk02026-06-02
v0.0.0-20260601030430-945b406f51ffLow risk02026-06-02
v0.0.0-20260531152017-86ecea47ef80Low risk02026-06-01
v0.0.0-20260531065358-7bfdeea2361cLow risk02026-06-01
v0.0.0-20260530231006-0b0f8480dbccLow risk02026-05-31
v0.0.0-20260530103128-9a2496973b71Low risk02026-05-31
v0.0.0-20260529091914-f6e2248d1262Low risk02026-05-30
v0.0.0-20260527104648-f220aa2fe7a3Review412026-05-29

Block this in CI

PkgRadar gates github.com/apache/groovy (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/apache/[email protected]