PkgRadar

Go modules · proxy.golang.org

github.com/drn/dots

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260615203629-b8e56a5cabaa

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/drn/[email protected]/cli/commands/doctor/root.go
mediumRemote Payloadmatched "curl " · github.com/drn/[email protected]/cli/commands/install/pi.go
mediumRemote Payloadmatched "curl " · github.com/drn/[email protected]/cli/commands/install/tools.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/drn/[email protected]/cli/commands/install/vim.go
mediumRemote Payloadmatched "curl " · github.com/drn/[email protected]/cmd/gps/root.go
mediumRemote Payloadmatched "curl " · github.com/drn/[email protected]/cmd/ip/external.go
mediumRemote Payloadmatched "curl " · github.com/drn/[email protected]/cmd/weather/openweather/root.go
mediumRemote Payloadmatched "curl " · github.com/drn/[email protected]/cmd/weather/wttr/root.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260615203629-b8e56a5cabaaHigh risk622026-06-16
v0.0.0-20260613064227-e4b8737a38c0High risk622026-06-14
v0.0.0-20260613061754-ee9401132d5dHigh risk622026-06-14
v0.0.0-20260612235820-95ac7d436586High risk622026-06-14
v0.0.0-20260612004609-a7d02155265bHigh risk622026-06-13
v0.0.0-20260611004632-2bf318c55385High risk622026-06-12
v0.0.0-20260605032009-868b2ba46dd6High risk622026-06-07
v0.0.0-20260526185017-20484a3f0486Review622026-05-30

Block this in CI

PkgRadar gates github.com/drn/dots (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/drn/[email protected]