PkgRadar

Go modules · proxy.golang.org

github.com/faasile-stein/bootload/cli-tools

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260615092821-60800d29c8c8

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/faasile-stein/bootload/[email protected]/internal/cli/backup.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260615092821-60800d29c8c8Review122026-06-16
v0.0.0-20260615075037-240785c67350Review122026-06-16
v0.0.0-20260615070335-f06ec4291986Review122026-06-16
v0.0.0-20260615070207-1d67847e1c03Review122026-06-16
v0.0.0-20260614215102-9ae0a0cb3b19Low risk02026-06-16
v0.0.0-20260614180928-cb8fa26440f1Low risk02026-06-15
v0.0.0-20260614174636-8b6138cbacebLow risk02026-06-15
v0.0.0-20260614165151-62fe270862ecLow risk02026-06-15
v0.0.0-20260614153652-97a7cf9e1183Low risk02026-06-15

Block this in CI

PkgRadar gates github.com/faasile-stein/bootload/cli-tools (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/faasile-stein/bootload/[email protected]