PkgRadar

Go modules · proxy.golang.org

github.com/brandonmartin/beads

Remote Payload: matched "curl "

Why PkgRadar flagged v0.38.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/brandonmartin/[email protected]/cmd/bd/doctor/claude.go
mediumRemote Payloadmatched "curl " · github.com/brandonmartin/[email protected]/cmd/bd/doctor/version.go
mediumRemote Payloadmatched "curl " · github.com/brandonmartin/[email protected]/cmd/bd/init.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.59.0Review242026-06-13
v0.38.0High risk362026-06-13
v0.30.2Review242026-06-13
v1.0.1High risk362026-06-13
v0.30.0Review242026-06-13
v0.29.0Review242026-06-13
v0.55.1Review242026-06-13
v0.46.0High risk482026-06-13
v0.51.0Review242026-06-13
v0.47.2High risk482026-06-13
v0.17.0Low risk02026-06-13
v0.54.0Review242026-06-13
v0.9.10Low risk02026-06-13
v0.9.8Low risk02026-06-13
v0.28.0Review242026-06-13
v0.62.0Review242026-06-13
v0.56.1Review242026-06-13
v0.50.2High risk362026-06-13
v0.17.2Low risk02026-06-13
v0.39.1High risk362026-06-13
v0.24.2Review242026-06-13
v0.21.7Review122026-06-13
v0.9.6Low risk02026-06-13
v0.48.0High risk482026-06-13
v0.24.1Review242026-06-13
v0.11.0Low risk02026-06-13
v0.44.0High risk482026-06-13
v1.0.4High risk482026-06-13
v1.0.6-0.20260612154203-1825cf3572ceHigh risk482026-06-13
v1.0.5High risk482026-06-13
v0.17.7Low risk02026-06-13

Block this in CI

PkgRadar gates github.com/brandonmartin/beads (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/brandonmartin/[email protected]