PkgRadar

Go modules · proxy.golang.org

github.com/deepflowio/deepflow/server

Remote Payload: matched "curl "

Why PkgRadar flagged v1.6.66-0.20260616064847-7f506bf768da

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/deepflowio/deepflow/[email protected]/controller/cloud/qingcloud/qingcloud.go
mediumRemote Payloadmatched "curl " · github.com/deepflowio/deepflow/[email protected]/controller/common/curl.go
mediumRemote Payloadmatched "curl " · github.com/deepflowio/deepflow/[email protected]/controller/genesis/common/utils.go
mediumRemote Payloadmatched "curl " · github.com/deepflowio/deepflow/[email protected]/controller/http/service/rebalance/traffic.go
mediumRemote Payloadmatched "curl " · github.com/deepflowio/deepflow/[email protected]/controller/http/service/vtap/vtap_interface.go
mediumRemote Payloadmatched "curl " · github.com/deepflowio/deepflow/[email protected]/controller/monitor/common.go
mediumRemote Payloadmatched "CURL " · github.com/deepflowio/deepflow/[email protected]/controller/prometheus/grpcurl.go
mediumRemote Payloadmatched "curl " · github.com/deepflowio/deepflow/[email protected]/controller/prometheus/label.go
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/deepflowio/deepflow/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.6.66-0.20260616064847-7f506bf768daHigh risk842026-06-17
v0.0.0-20260616064847-7f506bf768daHigh risk842026-06-17
v1.6.66-0.20260610091150-81067bc622ceHigh risk742026-06-11
v1.6.66-0.20260609113727-4b4596e64a52High risk742026-06-10
v1.6.66-0.20260609091707-58bd792976c7High risk742026-06-10
v1.6.66-0.20260605024923-f93be50de618High risk842026-06-06
v0.0.0-20260605024923-f93be50de618High risk842026-06-06
v1.6.66-0.20260603033632-b50aaae1e5d7High risk842026-06-04
v0.0.0-20260603033632-b50aaae1e5d7High risk842026-06-04
v1.6.66-0.20260602025915-359adae39afdHigh risk742026-06-03
v1.6.66-0.20260601092918-d2b84a04287eHigh risk842026-06-02
v0.0.0-20260601092918-d2b84a04287eHigh risk842026-06-02
v1.6.66-0.20260601074731-c6ac7268a677High risk842026-06-02
v0.0.0-20260601074731-c6ac7268a677High risk842026-06-02
v1.6.66-0.20260531044132-cab55fa9bfcbHigh risk842026-06-01
v1.6.66-0.20260529182940-8f247ea30217Review842026-05-30
v1.6.66-0.20260528104504-1f1ef746754fHigh risk742026-05-30
v1.6.66-0.20260528095528-d4e4b1b28ef9High risk742026-05-30
v1.6.66-0.20260528092810-d2e5534044f8High risk742026-05-30
v1.6.66-0.20260528074717-85f35e0e7143High risk742026-05-30
v1.6.66-0.20260528063613-550f900c3cfeHigh risk742026-05-30
v0.0.0-20260528013250-9b823767ccd7High risk742026-05-30
v1.6.66-0.20260528013250-9b823767ccd7High risk742026-05-30
v0.0.0-20260529061808-7d018f44e54dReview842026-05-30
v1.6.66-0.20260529061808-7d018f44e54dReview842026-05-30
v0.0.0-20260529061555-0211bdd7f973Review742026-05-30
v1.6.66-0.20260529061555-0211bdd7f973Review742026-05-30
v0.0.0-20260529033122-cb829611791eReview742026-05-30
v1.6.66-0.20260529033122-cb829611791eReview742026-05-30

Block this in CI

PkgRadar gates github.com/deepflowio/deepflow/server (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/deepflowio/deepflow/[email protected]