PkgRadar

Go modules · proxy.golang.org

github.com/ccfos/nightingale/v6

Remote Payload: matched "curl "

Why PkgRadar flagged v6.7.3-0.20260601162544-297557952dc0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/ccfos/nightingale/[email protected]/aiagent/chat/actions.go
mediumRemote Payloadmatched "curl " · github.com/ccfos/nightingale/[email protected]/pkg/flashduty/post.go
mediumRemote Payloadmatched "curl " · github.com/ccfos/nightingale/[email protected]/pkg/poster/post.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v6.7.3-0.20260614163040-36ae9231acdcReview292026-06-16
v6.7.3-0.20260611130016-2f8f848569beReview292026-06-12
v6.7.3-0.20260608102144-270f7c1b4f42Review292026-06-12
v6.7.3-0.20260601162544-297557952dc0High risk412026-06-02

Block this in CI

PkgRadar gates github.com/ccfos/nightingale/v6 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/ccfos/nightingale/[email protected]