PkgRadar

Go modules · proxy.golang.org

github.com/eliahhango/omniscan

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260530152718-b4890defbe1b

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/eliahhango/[email protected]/cmd/omniscan/main.go
mediumRemote Payloadmatched "curl " · github.com/eliahhango/[email protected]/internal/report/generator.go
mediumRemote Payloadmatched "github.com/zaproxy/zaproxy/releases/download" · github.com/eliahhango/[email protected]/internal/scanner/orchestrator.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260530152718-b4890defbe1bHigh risk362026-05-31
v0.0.0-20260530151042-c31a57eee8c3Review242026-05-31
v0.0.0-20260530145722-3838ce26505aReview242026-05-31
v0.0.0-20260530143633-003f23df487aReview242026-05-31
v0.0.0-20260530141340-a4635c5e68faReview242026-05-31
v0.0.0-20260530135939-acd6ba580ceeReview242026-05-31
v0.0.0-20260530133221-635a073279b8Review242026-05-31
v0.0.0-20260530130005-242c008b205bReview242026-05-31
v0.0.0-20260530123134-b4fb9e2e40a5Review242026-05-31
v0.0.0-20260530121244-ffdec77ba5afReview122026-05-31
v0.0.0-20260530115041-bbe404f122f0Review122026-05-31
v0.0.0-20260530120814-7a02f84b8df3Review122026-05-31
v0.0.0-20260530113841-6734b4df48ebReview122026-05-31
v0.0.0-20260530113427-5c7de081132bLow risk02026-05-31
v0.0.0-20260530111406-ccc8314a983fLow risk02026-05-31
v0.0.0-20260530110528-70d92d3ecd93Low risk02026-05-31

Block this in CI

PkgRadar gates github.com/eliahhango/omniscan (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/eliahhango/[email protected]