PkgRadar

Go modules · proxy.golang.org

github.com/entireio/cli

Remote Payload: matched "curl "

Why PkgRadar flagged v0.7.6

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/entireio/[email protected]/cmd/entire/cli/versioncheck/versioncheck.go
mediumRemote Payloadmatched "cUrl " · github.com/entireio/[email protected]/internal/coreapi/oas_json_gen.go
mediumRemote Payloadmatched "cUrl " · github.com/entireio/[email protected]/internal/coreapi/oas_schemas_gen.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.7.6High risk362026-06-16
v0.7.6-nightly.202606140745.87512403High risk362026-06-15
v0.7.6-nightly.202606130727.ef7c706aHigh risk362026-06-14
v0.7.6-nightly.202606090725.7ef77eafHigh risk362026-06-10
v0.7.6-nightly.202606080755.f0e7e5b5High risk362026-06-09
v0.7.6-nightly.202606070732.ab2c6169.0.20260607150205-fe495147c2a9High risk362026-06-08
v0.7.6-nightly.202606070732.ab2c6169High risk362026-06-08
v0.7.6-0.20260606101851-c70d7cddf47bHigh risk362026-06-07
v0.7.6-nightly.202606050739.c8b5981eHigh risk362026-06-06
v0.7.6-0.20260604193115-af7136650916High risk362026-06-05
v0.7.6-0.20260604204338-4411b7b8da27High risk362026-06-05
v0.7.5High risk362026-06-05
v0.7.4-nightly.202606040747.b98014a6High risk362026-06-05
v0.7.5-0.20260604135800-d239d10af956High risk362026-06-05
v0.7.4-0.20260603161017-d54a4e82aba0High risk362026-06-05
v0.7.4-nightly.202606040747.b98014a6.0.20260604092351-8a435c986a7fHigh risk362026-06-05
v0.7.4-nightly.202606030753.317a6f99.0.20260603140546-06df606a3e19High risk362026-06-04
v0.7.3High risk362026-06-03
v0.7.0High risk362026-06-03
v0.6.4-nightly.202605300709.d0327df7Review122026-05-31
v0.6.4-nightly.202605280731.ce96edb4Review122026-05-30
v0.6.4-nightly.202605290731.822729f4Review122026-05-30

Block this in CI

PkgRadar gates github.com/entireio/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/entireio/[email protected]