PkgRadar

Go modules · proxy.golang.org

github.com/files-com/files-sdk-go/v3

DNS / OAST exfiltration: matched "burpcollaborator.net"

Why PkgRadar flagged v3.3.147

SeveritySignalEvidence
highDNS / OAST exfiltrationmatched "burpcollaborator.net" · github.com/files-com/files-sdk-go/[email protected]/user/fixtures/TestClient_Update.yaml

Scanned versions

VersionVerdictScoreScanned (UTC)
v3.3.147High risk502026-06-16
v3.3.146High risk502026-06-16
v3.3.145High risk502026-06-15
v3.3.144High risk502026-06-13
v3.3.143High risk502026-06-13
v3.3.141-0.20260611164145-834d48e7ac4dHigh risk502026-06-12
v3.3.140High risk502026-06-11
v3.3.138High risk502026-06-11
v3.3.137High risk502026-06-10
v3.3.136High risk502026-06-09
v3.3.135High risk502026-06-09
v3.3.133High risk502026-06-06
v3.3.132High risk502026-06-06
v3.3.131High risk502026-06-05
v3.3.130High risk502026-06-05
v3.3.129High risk502026-06-05
v3.3.128High risk502026-06-04
v3.3.126High risk502026-06-04
v3.3.125High risk502026-06-03
v3.3.124High risk502026-06-02
v3.3.123High risk502026-06-02
v3.3.122High risk502026-06-02
v3.3.121High risk502026-06-02
v3.3.120High risk502026-06-01
v3.3.119High risk502026-06-01
v3.3.117High risk502026-05-30

Block this in CI

PkgRadar gates github.com/files-com/files-sdk-go/v3 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/files-com/files-sdk-go/[email protected]