PkgRadar

Go modules · proxy.golang.org

github.com/darpanzope/compliancekit

DNS / OAST exfiltration: matched "dig +short TXT _dmarc.%s`, d),\n\t}, nil\n}\n\nfunc renderBashDMARCSubdomain(f compliancekit.Finding) (remediate.Snippet, error) {\n\treturn renderBashDMARCPolicy(f)\n}\nfunc renderBashDMARCPct(f compliancekit.Finding) (remediate.Snippet, error) {\n\treturn renderBashDMARCPolicy(f)\n}\nfunc renderBashDMARCRUA(f compliancekit.Finding) (remediate.Snippet, error) {\n\treturn renderBashDMARCPolicy(f)\n}\nfunc renderBashDMARCRUF(f compliancekit.Finding) (remediate.Snippet, error) {\n\treturn renderBashDMARCPolicy(f)\n}\n\nfunc renderBashSPFStrict(f compliancekit.Finding) (remediate.Snippet, error) {\n\td := bashDomain(f)\n\tbody := fmt.Sprintf(`# Find + update the root SPF TXT record terminator from ~all/?all to -all.\ndomain=%q\nrec_id=\"$("

Why PkgRadar flagged v1.19.2-0.20260529164013-88f9112c3d3f

SeveritySignalEvidence
highDNS / OAST exfiltrationmatched "dig +short TXT _dmarc.%s`, d),\n\t}, nil\n}\n\nfunc renderBashDMARCSubdomain(f compliancekit.Finding) (remediate.Snippet, error) {\n\treturn renderBashDMARCPolicy(f)\n}\nfunc renderBashDMARCPct(f compliancekit.Finding) (remediate.Snippet, error) {\n\treturn renderBashDMARCPolicy(f)\n}\nfunc renderBashDMARCRUA(f compliancekit.Finding) (remediate.Snippet, error) {\n\treturn renderBashDMARCPolicy(f)\n}\nfunc renderBashDMARCRUF(f compliancekit.Finding) (remediate.Snippet, error) {\n\treturn renderBashDMARCPolicy(f)\n}\n\nfunc renderBashSPFStrict(f compliancekit.Finding) (remediate.Snippet, error) {\n\td := bashDomain(f)\n\tbody := fmt.Sprintf(`# Find + update the root SPF TXT record terminator from ~all/?all to -all.\ndomain=%q\nrec_id=\"$(" · github.com/darpanzope/[email protected]/internal/remediate/bash/do_domains.go
mediumRemote Payloadmatched "curl " · github.com/darpanzope/[email protected]/internal/checks/digitalocean/functions_extra.go
mediumRemote Payloadmatched "curl " · github.com/darpanzope/[email protected]/internal/checks/digitalocean/network_extra.go
mediumRemote Payloadmatched "curl " · github.com/darpanzope/[email protected]/internal/checks/k8s/admission_extra.go
mediumRemote Payloadmatched "cURL " · github.com/darpanzope/[email protected]/internal/ingest/ocsf/types.go
mediumRemote Payloadmatched "curl " · github.com/darpanzope/[email protected]/internal/remediate/bash/do_account.go
mediumRemote Payloadmatched "curl " · github.com/darpanzope/[email protected]/internal/remediate/bash/do_functions.go
mediumRemote Payloadmatched "curl " · github.com/darpanzope/[email protected]/internal/remediate/bash/do_network.go
mediumRemote Payloadmatched "curl " · github.com/darpanzope/[email protected]/internal/remediate/doctl/do_functions.go
mediumRemote Payloadmatched "curl " · github.com/darpanzope/[email protected]/internal/remediate/doctl/do_network.go
mediumRemote Payloadmatched "curl " · github.com/darpanzope/[email protected]/internal/remediate/kubectl/admission_extra.go
mediumRemote Payloadmatched "curl " · github.com/darpanzope/[email protected]/internal/remediate/kubectl/managed_extra.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.19.2-0.20260529164013-88f9112c3d3fHigh risk1562026-05-30
v1.19.1High risk1562026-05-30
v1.19.0High risk1562026-05-30
v1.18.0High risk1562026-05-30
v1.19.2-0.20260529171505-c88d4f513542High risk1562026-05-30

Block this in CI

PkgRadar gates github.com/darpanzope/compliancekit (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/darpanzope/[email protected]