PkgRadar

Go modules · proxy.golang.org

github.com/bandithedoge/nixpkgs-firefox-darwin

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260528023219-4e2f996fb365

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/bandithedoge/[email protected]/update.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260612025134-fe4920058d27Low risk02026-06-13
v0.0.0-20260610024511-9336eb9a336bLow risk02026-06-11
v0.0.0-20260608025356-a2d5cea2bb7bLow risk02026-06-09
v0.0.0-20260605024506-5e702eb7e360Low risk02026-06-06
v0.0.0-20260604025702-0b6ddca85cc4Low risk02026-06-05
v0.0.0-20260603032818-c7185f89dca3Low risk02026-06-05
v0.0.0-20260602025301-c72685294d8cLow risk02026-06-03
v0.0.0-20260601025612-3a0cc3489e2eLow risk02026-06-02
v0.0.0-20260531024727-c6cead2e59dbLow risk02026-06-01
v0.0.0-20260530023036-ac289b6e74a0Low risk02026-05-31
v0.0.0-20260529023631-5a3e28d7c969Low risk02026-05-30
v0.0.0-20260528023219-4e2f996fb365Review122026-05-29

Block this in CI

PkgRadar gates github.com/bandithedoge/nixpkgs-firefox-darwin (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/bandithedoge/[email protected]