PkgRadar

Go modules · proxy.golang.org

github.com/docker/cagent

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged v1.72.1-0.20260602170615-e16fa6017e1b

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/docker/[email protected]/pkg/config/sources.go
mediumRemote Payloadmatched "github.com/%s/%s/releases/download" · github.com/docker/[email protected]/pkg/toolinstall/installer.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/docker/[email protected]/pkg/toolinstall/registry.go
mediumRemote Payloadmatched "cURL " · github.com/docker/[email protected]/pkg/tools/builtin/openapi/openapi.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.72.1-0.20260602170615-e16fa6017e1bHigh risk532026-06-03
v1.72.0High risk532026-06-03
v1.70.3-0.20260601154959-7b77592259a1High risk532026-06-02
v1.70.2High risk532026-06-02
v1.70.2-0.20260601115326-8de9c75ac023High risk532026-06-02
v1.70.1High risk532026-06-02
v1.69.0Review532026-05-29

Block this in CI

PkgRadar gates github.com/docker/cagent (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/docker/[email protected]