PkgRadar

Go modules · proxy.golang.org

github.com/cortezaproject/corteza-server/server

Remote Payload: matched "cUrl "

Why PkgRadar flagged v0.0.0-20260608075356-3b69e9f45140

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · github.com/cortezaproject/corteza-server/[email protected]/app/boot_levels.go
mediumRemote Payloadmatched "cUrl " · github.com/cortezaproject/corteza-server/[email protected]/auth/handlers/handler.go
mediumRemote Payloadmatched "cUrl " · github.com/cortezaproject/corteza-server/[email protected]/auth/settings/settings.go
mediumRemote Payloadmatched "curl " · github.com/cortezaproject/corteza-server/[email protected]/go.sum

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260608075356-3b69e9f45140High risk482026-06-11
v0.0.0-20260603120951-42dcf81a59f7High risk482026-06-06
v0.0.0-20260602142533-dc260b9935a4High risk482026-06-04
v0.0.0-20260526144241-b616f9a7580eReview482026-05-29

Block this in CI

PkgRadar gates github.com/cortezaproject/corteza-server/server (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/cortezaproject/corteza-server/[email protected]