PkgRadar

Go modules · proxy.golang.org

github.com/cplieger/vibekit

Remote Payload: matched "curl "

Why PkgRadar flagged v0.1.55

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/cplieger/[email protected]/internal/forges/install.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.1.1Low risk02026-06-16
v0.1.55Review122026-06-16
v0.1.25Review122026-06-16
v0.1.27Review122026-06-16
v0.1.40Review122026-06-16
v0.1.16Review122026-06-16
v0.1.28Review122026-06-16
v0.1.19Review122026-06-16
v0.1.54-0.20260615082019-1910d7d5ad91Review122026-06-16
v0.1.21Review122026-06-16
v0.1.18Review122026-06-16
v0.1.26Review122026-06-16
v0.1.34Review122026-06-16
v0.1.48Review122026-06-16
v0.1.46Review122026-06-16
v0.1.42Review122026-06-16
v0.1.54-0.20260615070641-56b0d782861dReview122026-06-16

Block this in CI

PkgRadar gates github.com/cplieger/vibekit (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/cplieger/[email protected]