PkgRadar

Go modules · proxy.golang.org

github.com/contenox/runtime

Remote Payload: matched "curl "

Why PkgRadar flagged v0.31.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/contenox/[email protected]/runtime/contenoxcli/init.go
mediumRemote Payloadmatched "github.com/contenox/runtime/releases/download" · github.com/contenox/[email protected]/runtime/contenoxcli/update_cmd.go
mediumRemote Payloadmatched "cURL " · github.com/contenox/[email protected]/runtime/runtimetypes/store.go
mediumRemote Payloadmatched "cURL " · github.com/contenox/[email protected]/runtime/toolsproviderservice/toolsproviderservice.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.31.0High risk672026-06-15
v0.28.14High risk552026-06-12
v0.28.13High risk552026-06-12
v0.28.12High risk552026-06-11
v0.28.9High risk552026-06-10
v0.28.6High risk552026-06-10
v0.28.7High risk552026-06-10
v0.28.8High risk552026-06-10
v0.28.5High risk552026-06-09
v0.28.3High risk552026-06-09
v0.28.2-0.20260606120416-18ee5b419352High risk502026-06-08
v0.28.1High risk502026-06-08
v0.28.0High risk502026-06-06
v0.25.4High risk502026-06-05
v0.25.1-0.20260528203417-a5ab004509e9Review502026-05-30
v0.25.0Review502026-05-30

Block this in CI

PkgRadar gates github.com/contenox/runtime (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/contenox/[email protected]