PkgRadar

Go modules · proxy.golang.org

github.com/google/go-tpm-tools

Remote Payload: matched "curl "

Why PkgRadar flagged v0.4.8-0.20260129213742-641fb37dacda

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/google/[email protected]/go.sum

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.4.8-0.20260129213742-641fb37dacdaReview122026-06-13
v0.4.10-0.20260609210751-cd1e39201697Review122026-06-11
v0.0.0-20260609210751-cd1e39201697Review122026-06-11
v0.4.10-0.20260608214720-9ab0d937a58bReview122026-06-10
v0.0.0-20260608214720-9ab0d937a58bReview122026-06-10
v0.4.10-0.20260606014948-fdb32df31d98Review122026-06-07
v0.0.0-20260606014948-fdb32df31d98Review122026-06-07
v0.4.9Review122026-06-06
v0.4.9-0.20260604231049-79b91b3d1c4fReview122026-06-06
v0.0.0-20260604231049-79b91b3d1c4fReview122026-06-06
v0.4.9-0.20260604000217-49f85f000cddReview122026-06-05
v0.0.0-20260604000217-49f85f000cddReview122026-06-05
v0.0.0-20260603173636-60d76aee6cb4Review122026-06-04
v0.0.0-20260603071417-41f336113c69Review122026-06-04
v0.0.0-20260602053106-0acabcbe916aReview122026-06-03
v0.4.9-0.20260602002757-0785c84e27e6Review122026-06-03
v0.0.0-20260602002757-0785c84e27e6Review122026-06-03
v0.4.9-0.20260323064108-c13cba1b7b70Review122026-06-02
v0.0.0-20260601203525-bc0d334a930fReview122026-06-02
v0.4.9-0.20260529154125-a13147064073Review122026-05-31
v0.0.0-20260529154125-a13147064073Review122026-05-31
v0.0.0-20260528214641-aeb0907f0ea1Review122026-05-29

Block this in CI

PkgRadar gates github.com/google/go-tpm-tools (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/google/[email protected]