PkgRadar

Go modules · proxy.golang.org

github.com/google/go-tpm-tools/agent

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260611092415-555255f7438e

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/google/go-tpm-tools/[email protected]/go.sum

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260611092415-555255f7438eReview122026-06-12
v0.0.0-20260606180017-acf3acf5c9e2Review122026-06-08
v0.0.0-20260606014948-fdb32df31d98Review122026-06-07
v0.0.0-20260604000217-49f85f000cddReview122026-06-05
v0.0.0-20260603173636-60d76aee6cb4Review122026-06-04
v0.0.0-20260603071417-41f336113c69Review122026-06-04
v0.0.0-20260602002757-0785c84e27e6Review122026-06-03
v0.0.0-20260529154125-a13147064073Review122026-06-01

Block this in CI

PkgRadar gates github.com/google/go-tpm-tools/agent (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/google/go-tpm-tools/[email protected]