PkgRadar

Go modules · proxy.golang.org

github.com/duggaraju/c2pa-go/c2pa

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v0.87.0

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/duggaraju/c2pa-go/[email protected]/generate_debug_unix.go
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/duggaraju/c2pa-go/[email protected]/generate_release_unix.go
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/duggaraju/c2pa-go/[email protected]/schema/generate_unix.go
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/duggaraju/c2pa-go/[email protected]/schema/generate_windows.go
mediumRemote Payloadmatched "github.com/%s/releases/download" · github.com/duggaraju/c2pa-go/[email protected]/cmd/fetchlib/main.go
mediumRemote Payloadmatched "curl " · github.com/duggaraju/c2pa-go/[email protected]/native.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.87.0Review742026-06-12
v0.86.1Review742026-06-11
v0.86.0Review742026-06-09
v0.85.2Review742026-06-05
v0.84.2-0.20260602010232-8f3da90e6ca7Review742026-06-03
v0.85.1Review742026-06-03

Block this in CI

PkgRadar gates github.com/duggaraju/c2pa-go/c2pa (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/duggaraju/c2pa-go/[email protected]