PkgRadar

Go modules · proxy.golang.org

github.com/caddyserver/caddy/v2

Remote Payload: matched "curl "

Why PkgRadar flagged v2.7.3-0.20230803185347-c049bab4580c

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/caddyserver/caddy/[email protected]/go.sum

Scanned versions

VersionVerdictScoreScanned (UTC)
v2.11.5-0.20260607161820-55b3397a2da2Low risk02026-06-08
v2.7.3-0.20230803185347-c049bab4580cReview122026-06-08
v2.11.5-0.20260606210251-d3986f824d2eLow risk02026-06-07
v2.11.5-0.20260606201001-fafe4e2dee76Low risk02026-06-07
v2.11.5-0.20260606184224-2cf31be53f89Low risk02026-06-07
v2.11.5-0.20260606173049-3eecde2c99c0Low risk02026-06-07
v2.11.5-0.20260606151401-8bb78d671dd7Low risk02026-06-07
v2.11.5-0.20260605184344-c67ace99497fLow risk02026-06-06
v2.11.4-0.20260605162647-7e5b614ed098Low risk02026-06-06
v2.11.5-0.20260605014135-d730df2a83e8Low risk02026-06-06
v2.11.5-0.20260604185508-3b7bde8f2512Low risk02026-06-05
v2.11.5-0.20260604150319-915793f6e009Low risk02026-06-05
v2.11.5-0.20260603050258-df91fb0da936Low risk02026-06-04
v2.11.5-0.20260603034900-fcc7860d038aLow risk02026-06-04
v2.11.4Low risk02026-06-04
v2.11.4-0.20260603010745-3f71b5e1f397Low risk02026-06-04
v2.11.4-0.20260601193502-e2eee6a7fce3Low risk02026-06-02
v2.11.4-0.20260529210541-0e8eb41b87abLow risk02026-05-30
v2.11.4-0.20260529173717-3eb8e48ff052Low risk02026-05-30
v2.11.4-0.20260528011809-86121c860f59Low risk02026-05-30
v2.11.4-0.20260528192619-03e08ee6a9cfLow risk02026-05-29

Block this in CI

PkgRadar gates github.com/caddyserver/caddy/v2 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/caddyserver/caddy/[email protected]