PkgRadar

Go modules · proxy.golang.org

github.com/contenox/runtime-mvp

Remote Payload: matched "curl "

Why PkgRadar flagged v0.31.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/contenox/[email protected]/runtime/contenoxcli/init.go
mediumRemote Payloadmatched "github.com/contenox/runtime/releases/download" · github.com/contenox/[email protected]/runtime/contenoxcli/update_cmd.go
mediumRemote Payloadmatched "cURL " · github.com/contenox/[email protected]/runtime/runtimetypes/store.go
mediumRemote Payloadmatched "cURL " · github.com/contenox/[email protected]/runtime/toolsproviderservice/toolsproviderservice.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.31.0High risk672026-06-15
v0.28.6High risk552026-06-12
v0.28.8High risk552026-06-12
v0.28.13High risk552026-06-12
v0.28.11High risk552026-06-12
v0.28.10High risk552026-06-11
v0.28.9High risk552026-06-10
v0.28.4High risk552026-06-09
v0.28.2High risk552026-06-09
v0.28.0High risk502026-06-09
v0.28.5High risk552026-06-09
v0.28.3High risk552026-06-09
v0.28.2-0.20260606120416-18ee5b419352High risk502026-06-08
v0.28.1High risk502026-06-08
v0.27.1High risk502026-06-02
v0.27.0High risk502026-06-01
v0.26.1-0.20260531122815-132adc9ef976High risk502026-06-01
v0.26.0High risk502026-06-01
v0.25.1-0.20260528203417-a5ab004509e9Review502026-05-29
v0.25.0Review502026-05-29

Block this in CI

PkgRadar gates github.com/contenox/runtime-mvp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/contenox/[email protected]