PkgRadar

Go modules · proxy.golang.org

github.com/google/go-containerregistry

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260612174616-02649eab0d52

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/google/[email protected]/cmd/crane/cmd/auth.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20200115185706-556f30d79a38Low risk02026-06-16
v0.0.0-20260612174616-02649eab0d52Review122026-06-13
v0.0.0-20240717013255-c3d1dcc93207Review122026-06-13
v0.21.7-0.20260611222238-4cfaa93eb444Review122026-06-12
v0.0.0-20260611222238-4cfaa93eb444Review122026-06-12
v0.21.7-0.20260604213829-6849394e8a65Review122026-06-05
v0.0.0-20260604213829-6849394e8a65Review122026-06-05
v0.21.7-0.20260604212323-ebd9e4a92792Review122026-06-05
v0.0.0-20260604212323-ebd9e4a92792Review122026-06-05
v0.0.0-20260602205845-4b7672c7705aReview122026-06-03
v0.0.0-20260602185054-06ee04923544Review122026-06-03
v0.21.7-0.20260602184325-7f937fe593c4Review122026-06-03
v0.0.0-20260602182410-e8f7b82ff062Review122026-06-03

Block this in CI

PkgRadar gates github.com/google/go-containerregistry (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/google/[email protected]