PkgRadar

Go modules · proxy.golang.org

github.com/cpusoft/goutil

Remote Payload: matched "curl "

Why PkgRadar flagged v1.0.33-0.20260616105340-377bdd1a898f

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/cpusoft/[email protected]/rrdputil/rrdpdelta.go
mediumRemote Payloadmatched "curl " · github.com/cpusoft/[email protected]/rrdputil/rrdpnotification.go
mediumRemote Payloadmatched "cUrl " · github.com/cpusoft/[email protected]/rsyncutil/rsyncmodel.go
mediumRemote Payloadmatched "cUrl " · github.com/cpusoft/[email protected]/rsyncutil/rsyncutil.go
mediumRemote Payloadmatched "cUrl " · github.com/cpusoft/[email protected]/talutil/parsetal.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.0.33-0.20260616105340-377bdd1a898fHigh risk602026-06-17
v1.0.33-0.20260616021738-0bd7e414d151High risk602026-06-17
v1.0.33-0.20260605080853-92a282bf4228High risk602026-06-06
v1.0.33-0.20260605080518-0a7ea234ff35High risk602026-06-06
v1.0.33-0.20260603080949-ba8aca512564High risk602026-06-04
v1.0.33-0.20260602033603-033edf2a83abHigh risk602026-06-03
v1.0.33-0.20260531163650-24d4df715e35High risk602026-06-01
v1.0.33-0.20260530041403-6c2facf54b94Review602026-05-31
v1.0.33-0.20260529030425-e09989fef688Review602026-05-30

Block this in CI

PkgRadar gates github.com/cpusoft/goutil (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/cpusoft/[email protected]