PkgRadar

Go modules · proxy.golang.org

github.com/gentleman-programming/gentleman-ai-installer

Remote Payload: matched "curl "

Why PkgRadar flagged v1.39.3

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/gentleman-programming/[email protected]/internal/update/instructions.go
mediumRemote Payloadmatched "github.com/%s/%s/releases/download" · github.com/gentleman-programming/[email protected]/internal/update/upgrade/download.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.39.3Review292026-06-14
v1.37.1Review292026-06-14
v1.39.2Review292026-06-14
v1.39.1Review292026-06-14
v1.38.0Review292026-06-14
v1.37.0Review292026-06-14
v1.36.7Review292026-06-14
v1.39.0Review292026-06-14
v1.40.2Review292026-06-14
v1.40.1Review292026-06-14
v1.37.2Review292026-06-12
v1.36.8Review292026-06-12
v1.36.6Review292026-06-12
v1.36.5Review292026-06-07
v1.36.3Review292026-06-07
v1.34.0Review292026-06-07
v1.36.2Review292026-06-07
v1.31.0Review242026-05-30
v1.32.1-0.20260527170700-412eed3d39deReview292026-05-30
v1.30.9Review242026-05-30
v1.30.10Review242026-05-30
v1.32.0Review242026-05-30

Block this in CI

PkgRadar gates github.com/gentleman-programming/gentleman-ai-installer (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/gentleman-programming/[email protected]