PkgRadar

Go modules · proxy.golang.org

github.com/formancehq/payments

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.0.0-20260612142110-8c3a622bf113

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/formancehq/[email protected]/internal/connectors/engine/engine.go
mediumRemote Payloadmatched "cURL " · github.com/formancehq/[email protected]/internal/connectors/engine/module.go
mediumRemote Payloadmatched "cURL " · github.com/formancehq/[email protected]/internal/connectors/engine/utils/utils.go
mediumRemote Payloadmatched "cURL " · github.com/formancehq/[email protected]/internal/connectors/engine/workflow/workflow.go
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/formancehq/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260612142110-8c3a622bf113High risk582026-06-13
v0.0.0-20260612094403-051060c12117High risk582026-06-13
v0.0.0-20260610082407-b458f7dc5827High risk582026-06-11
v0.0.0-20260609095316-0a97064df964High risk582026-06-10
v0.0.0-20260608120953-d214143138f8High risk582026-06-10
v0.0.0-20260605131309-b251598c4e7dHigh risk582026-06-07
v0.0.0-20260528152536-b6c87aa17331Review582026-05-30

Block this in CI

PkgRadar gates github.com/formancehq/payments (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/formancehq/[email protected]