PkgRadar

Go modules · proxy.golang.org

github.com/apache/thrift

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260528074315-7d9a69abf303

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/apache/[email protected]/docker/update.sh
mediumRemote Payloadmatched "curl " · github.com/apache/[email protected]/lib/cl/ensure-externals.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.23.1-0.20260603002616-318212b93859Low risk02026-06-04
v0.0.0-20260603002616-318212b93859Low risk02026-06-04
v0.0.0-20260603001653-027e3762b09dLow risk02026-06-04
v0.23.1-0.20260602062223-f69b418f1f2bLow risk02026-06-03
v0.0.0-20260602062223-f69b418f1f2bLow risk02026-06-03
v0.23.1-0.20260601221638-9bc9c9379b82Low risk02026-06-02
v0.0.0-20260601221638-9bc9c9379b82Low risk02026-06-02
v0.23.1-0.20260601220352-aeeaf4bf3953Low risk02026-06-02
v0.0.0-20260601215513-9b5887a4f488Low risk02026-06-02
v0.0.0-20260601211620-65f6d60a344bLow risk02026-06-02
v0.23.1-0.20260601204729-762455591487Low risk02026-06-02
v0.23.1-0.20260531231345-7107195895ceLow risk02026-06-01
v0.0.0-20260531231345-7107195895ceLow risk02026-06-01
v0.0.0-20260531225432-bcd91a392a1bLow risk02026-06-01
v0.0.0-20260531225148-b621b536d01eLow risk02026-06-01
v0.0.0-20260531220727-69d314cc2552Low risk02026-06-01
v0.23.1-0.20260531220727-69d314cc2552Low risk02026-06-01
v0.0.0-20260530222330-5e29f31685b6Low risk02026-05-31
v0.23.1-0.20260530222330-5e29f31685b6Low risk02026-05-31
v0.23.1-0.20260530101810-af4f530c05a3Low risk02026-05-31
v0.0.0-20260530101810-af4f530c05a3Low risk02026-05-31
v0.0.0-20260530084846-70a1e819637dLow risk02026-05-31
v0.23.1-0.20260529221238-a3c91a62a80fLow risk02026-05-30
v0.0.0-20260529221238-a3c91a62a80fLow risk02026-05-30
v0.23.1-0.20260529134054-7a3e7bd1565cLow risk02026-05-30
v0.0.0-20260529134054-7a3e7bd1565cLow risk02026-05-30
v0.23.1-0.20260529123111-9c7c8e6e960dLow risk02026-05-30
v0.0.0-20260529123111-9c7c8e6e960dLow risk02026-05-30
v0.23.1-0.20260529002519-1ffdcf24e4abLow risk02026-05-30
v0.0.0-20260529002519-1ffdcf24e4abLow risk02026-05-30
v0.23.1-0.20260528234036-154e81a33419Low risk02026-05-30
v0.23.1-0.20260528224730-f3a7780515a4Low risk02026-05-29
v0.0.0-20260528214008-d6b2f4f21172Low risk02026-05-29
v0.23.1-0.20260528213210-655cc2b122deLow risk02026-05-29
v0.0.0-20260528213210-655cc2b122deLow risk02026-05-29
v0.23.1-0.20260528142805-40268d906291Low risk02026-05-29
v0.0.0-20260528142805-40268d906291Low risk02026-05-29
v0.0.0-20260528074315-7d9a69abf303Review242026-05-29
v0.23.1-0.20260528000148-0a8d92cb6562Review242026-05-29
v0.0.0-20260528000148-0a8d92cb6562Review242026-05-29

Block this in CI

PkgRadar gates github.com/apache/thrift (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/apache/[email protected]