PkgRadar

Go modules · proxy.golang.org

github.com/footprintai/containarium

Remote Payload: matched "wget "

Why PkgRadar flagged v0.30.0

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · github.com/footprintai/[email protected]/internal/app/buildpack/static.go
mediumRemote Payloadmatched "curl " · github.com/footprintai/[email protected]/internal/cmd/expose_port.go
mediumRemote Payloadmatched "cURL " · github.com/footprintai/[email protected]/internal/cmd/hosting_providers.go
mediumRemote Payloadmatched "curl " · github.com/footprintai/[email protected]/internal/cmd/hosting_setup.go
mediumRemote Payloadmatched "curl " · github.com/footprintai/[email protected]/internal/cmd/login.go
mediumRemote Payloadmatched "curl " · github.com/footprintai/[email protected]/internal/cmd/token.go
mediumRemote Payloadmatched "curl " · github.com/footprintai/[email protected]/internal/mcp/tools.go
mediumRemote Payloadmatched "github.com/projectdiscovery/nuclei/releases/download" · github.com/footprintai/[email protected]/internal/pentest/installer.go
mediumRemote Payloadmatched "github.com/open-telemetry/opentelemetry-collector-releases/releases/download" · github.com/footprintai/[email protected]/internal/server/core_otel_collector.go
mediumRemote Payloadmatched "wget " · github.com/footprintai/[email protected]/internal/server/core_services.go
mediumRemote Payloadmatched "github.com/zaproxy/zaproxy/releases/download" · github.com/footprintai/[email protected]/internal/zap/installer.go
mediumRemote Payloadmatched "curl " · github.com/footprintai/[email protected]/pkg/core/coresys/manager.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.30.0High risk1552026-06-17
v0.29.0High risk1552026-06-16
v0.28.0High risk1552026-06-15
v0.26.7-0.20260612145241-cf8d443f4e57High risk1552026-06-13
v0.26.7-0.20260612144532-bb39d16c7a8eHigh risk1552026-06-13
v0.26.7-0.20260612134104-a56ed0cd7083High risk1552026-06-13
v0.26.6High risk1552026-06-13
v0.26.5-0.20260610114232-8f7bcab06c5aHigh risk1552026-06-12
v0.26.0High risk1552026-06-12
v0.25.1-0.20260608133813-a8875f57bfb9High risk1552026-06-09
v0.25.0High risk1552026-06-09
v0.22.8High risk1552026-06-07
v0.22.3High risk1652026-06-07
v0.22.6High risk1552026-06-07
v0.23.3-0.20260606154743-53213eb1836dHigh risk1552026-06-07
v0.23.2High risk1552026-06-07
v0.22.9High risk1552026-06-07
v0.22.7High risk1552026-06-07
v0.22.1High risk1652026-06-07
v0.23.0High risk1552026-06-07
v0.22.10High risk1552026-06-06
v0.22.2High risk1652026-06-04
v0.22.5-0.20260603073548-a946641c26f4High risk1652026-06-04
v0.22.4High risk1652026-06-04
v0.22.0High risk1652026-06-02
v0.19.2High risk1652026-05-30
v0.19.1High risk1652026-05-30
v0.19.0High risk1652026-05-30
v0.18.1High risk1502026-05-30
v0.19.3High risk1652026-05-30
v0.21.1-0.20260529064447-5376b9e89c9fReview1652026-05-30
v0.21.0Review1652026-05-30

Block this in CI

PkgRadar gates github.com/footprintai/containarium (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/footprintai/[email protected]