PkgRadar

Go modules · proxy.golang.org

github.com/chaitin/MonkeyCode/backend

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260602152133-f95fd7ed56a9

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/chaitin/monkeycode/[email protected]/biz/host/usecase/host.go
mediumRemote Payloadmatched "curl " · github.com/chaitin/monkeycode/[email protected]/biz/team/usecase/host.go
mediumRemote Payloadmatched "cURL " · github.com/chaitin/monkeycode/[email protected]/config/config.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260602152133-f95fd7ed56a9High risk362026-06-03
v0.0.0-20260602115951-cc284794939aHigh risk362026-06-03
v0.0.0-20260602042905-64be13b870aeHigh risk362026-06-03
v0.0.0-20260602032608-a38033d3388fHigh risk362026-06-03
v0.0.0-20260601115221-c83c53279f28High risk362026-06-02
v0.0.0-20260601104125-7086fdfbd00aHigh risk362026-06-02
v0.0.0-20260601105346-c438f65e0ddcHigh risk362026-06-02
v0.0.0-20260528103527-b4135f9609b0High risk602026-05-30
v0.0.0-20260528095916-4a4e58b9791cHigh risk602026-05-30
v0.0.0-20260528091357-929f721cf771High risk602026-05-30
v0.0.0-20260529115744-607164b191dbReview362026-05-30
v0.0.0-20260529064413-82e9061e65e5Review362026-05-30

Block this in CI

PkgRadar gates github.com/chaitin/MonkeyCode/backend (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/chaitin/MonkeyCode/[email protected]