PkgRadar

Go modules · proxy.golang.org

github.com/ethereum-optimism/superchain-registry/ops

Remote Payload: matched "CURL "

Why PkgRadar flagged v0.0.0-20260611202829-ac4e48516794

SeveritySignalEvidence
mediumRemote Payloadmatched "CURL " · github.com/ethereum-optimism/superchain-registry/[email protected]/cmd/print_staging_report/main.go
mediumRemote Payloadmatched "cUrl " · github.com/ethereum-optimism/superchain-registry/[email protected]/cmd/sync_staging/main.go
mediumRemote Payloadmatched "cUrl " · github.com/ethereum-optimism/superchain-registry/[email protected]/internal/manage/fetch_onchain.go
mediumRemote Payloadmatched "cUrl " · github.com/ethereum-optimism/superchain-registry/[email protected]/internal/report/all.go
mediumRemote Payloadmatched "cUrl " · github.com/ethereum-optimism/superchain-registry/[email protected]/internal/report/l2.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260611202829-ac4e48516794High risk602026-06-13
v0.0.0-20260610180745-f3e94ce4f757High risk602026-06-12
v0.0.0-20260606151527-97f3aa2c2826High risk602026-06-08
v0.0.0-20260601151045-c90d86d2ed13High risk602026-06-02
v0.0.0-20260529163106-8b1e9dbca4ddHigh risk602026-06-01

Block this in CI

PkgRadar gates github.com/ethereum-optimism/superchain-registry/ops (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/ethereum-optimism/superchain-registry/[email protected]