PkgRadar

Go modules · proxy.golang.org

github.com/cockroachdb/cockroach/pkg/acceptance/compose/gss/psql

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260606144702-5f5932a2bf50

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/cockroachdb/cockroach/pkg/acceptance/compose/gss/[email protected]/go.sum

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260606144702-5f5932a2bf50Review122026-06-09
v0.0.0-20260603230306-76ca11f15900Review122026-06-05
v0.0.0-20260602213355-c91826fd4a4bReview122026-06-04
v0.0.0-20260602130518-0eedd74aedeeReview122026-06-03
v0.0.0-20260602115634-aa723a0f100bReview122026-06-03
v0.0.0-20260602111051-8ad63ef499c5Review122026-06-03
v0.0.0-20260602103305-bb2461a7edecReview122026-06-03
v0.0.0-20260602101219-78450ef4b4c6Review122026-06-03
v0.0.0-20260602085844-b8b50a4ab84cReview122026-06-03
v0.0.0-20260602065031-3eb31daea115Review122026-06-03
v0.0.0-20260602044119-214445a64729Review122026-06-03
v0.0.0-20260528181025-d9137701cbf9Review122026-05-29

Block this in CI

PkgRadar gates github.com/cockroachdb/cockroach/pkg/acceptance/compose/gss/psql (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/cockroachdb/cockroach/pkg/acceptance/compose/gss/[email protected]