PkgRadar

Go modules · proxy.golang.org

github.com/foliagecp/sdk

Remote Payload: matched "curl "

Why PkgRadar flagged v0.2.6-dev27052026

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/foliagecp/[email protected]/tests/soak/_lib/compose.sh
mediumRemote Payloadmatched "curl " · github.com/foliagecp/[email protected]/tests/soak/leak-hunt/run.sh
mediumRemote Payloadmatched "curl " · github.com/foliagecp/[email protected]/tests/system/_lib/compose.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.2.9-dev03062026Low risk02026-06-05
v0.2.7-dev28052026Low risk02026-06-02
v0.2.6-dev27052026Review362026-05-29

Block this in CI

PkgRadar gates github.com/foliagecp/sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/foliagecp/[email protected]
github.com/foliagecp/sdk — Go modules security scan | PkgRadar