PkgRadar

Go modules · proxy.golang.org

github.com/firebase/genkit/go

Remote Payload: matched "curl "

Why PkgRadar flagged v1.8.1-0.20260527233343-30f90bd508a3

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/firebase/genkit/[email protected]/samples/cloud_run_request.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.8.1-0.20260613163158-0fe54370063fLow risk02026-06-16
v1.8.1-0.20260612093345-212e602d8833Low risk02026-06-13
v1.8.1-0.20260609202337-2b468ac386aeLow risk02026-06-10
v1.8.1-0.20260603162807-c6b7727d3879Low risk02026-06-05
v1.8.1-0.20260601171605-6a0b663bb8feLow risk02026-06-03
v1.8.1-0.20260528203425-4b41851fafe0Low risk02026-05-30
v1.8.1-0.20260527233343-30f90bd508a3Review122026-05-29

Block this in CI

PkgRadar gates github.com/firebase/genkit/go (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/firebase/genkit/[email protected]