PkgRadar

Go modules · proxy.golang.org

github.com/dapr/components-contrib

Remote Payload: matched "curl "

Why PkgRadar flagged v1.18.0-rc.1.0.20260611165959-f125c43e805f

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/dapr/[email protected]/go.mod
mediumRemote Payloadmatched "curl " · github.com/dapr/[email protected]/go.sum

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.18.0-rc.1.0.20260611165959-f125c43e805fReview242026-06-12
v1.17.7Review242026-06-09
v1.18.0-rc.2Review242026-06-09
v1.12.0-rc.4.0.20231101224922-8680e2785acaReview242026-06-08
v1.18.0-rc.1.0.20260601203213-0d6569ac4373Review242026-06-02
v0.0.0-20260601203213-0d6569ac4373Review242026-06-02
v0.0.0-20260528160629-1a336c166dd3Review242026-05-29

Block this in CI

PkgRadar gates github.com/dapr/components-contrib (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/dapr/[email protected]