PkgRadar

Go modules · proxy.golang.org

github.com/getplumber/plumber

Remote Payload: matched "cURL\n\t\t"

Why PkgRadar flagged v0.3.39-0.20260602094349-e556a1a0ee10

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL\n\t\t" · github.com/getplumber/[email protected]/cmd/glsast.go
mediumRemote Payloadmatched "cURL " · github.com/getplumber/[email protected]/cmd/render_details.go
mediumRemote Payloadmatched "cURL\n\t\t\t" · github.com/getplumber/[email protected]/cmd/sarif.go
mediumRemote Payloadmatched "cURL\n\t" · github.com/getplumber/[email protected]/control/badge.go
mediumRemote Payloadmatched "cURL " · github.com/getplumber/[email protected]/control/mrcomment.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.3.39-0.20260602094349-e556a1a0ee10High risk602026-06-04
v0.3.33High risk602026-06-04
v0.3.29High risk602026-06-04
v0.3.34High risk602026-06-04
v0.3.36High risk602026-06-04
v0.3.35High risk602026-06-04
v0.3.37High risk602026-06-04
v0.3.30High risk602026-06-04
v0.3.31High risk602026-06-04
v0.3.28High risk602026-06-04
v0.3.32High risk602026-06-04
v0.3.38High risk602026-06-04
v0.3.22Review602026-05-29
v0.3.19Review602026-05-29
v0.3.18Review602026-05-29
v0.3.21Review602026-05-29
v0.3.28-0.20260526132657-7c7834414bcfReview602026-05-29

Block this in CI

PkgRadar gates github.com/getplumber/plumber (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/getplumber/[email protected]