PkgRadar

Go modules · proxy.golang.org

github.com/gastownhall/beads

Remote Payload: matched "curl "

Why PkgRadar flagged v1.0.6-0.20260615070122-8e18581dc0dd

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/gastownhall/[email protected]/cmd/bd/doctor/version.go
mediumRemote Payloadmatched "cURL " · github.com/gastownhall/[email protected]/cmd/bd/init.go
mediumRemote Payloadmatched "curl " · github.com/gastownhall/[email protected]/cmd/bd/init_templates.go
mediumRemote Payloadmatched "curl " · github.com/gastownhall/[email protected]/cmd/bd/store_factory_nocgo.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.0.6-0.20260615070122-8e18581dc0ddHigh risk482026-06-16
v1.0.6-0.20260613111428-e8ae7a291a39High risk482026-06-14
v1.0.6-0.20260605211334-0da7f51f3bcbHigh risk482026-06-08
v1.0.6-0.20260603223755-a5e5cd71f15cHigh risk482026-06-05
v1.0.6-0.20260531005639-848d0d7b6c93High risk482026-06-01
v1.0.5Review482026-05-30

Block this in CI

PkgRadar gates github.com/gastownhall/beads (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/gastownhall/[email protected]