Go modules · proxy.golang.org
github.com/google/go-tpm-tools/verifier
Remote Payload: matched "curl "
Why PkgRadar flagged v0.0.0-20260529154125-a13147064073
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "curl " · github.com/google/go-tpm-tools/[email protected]/go.sum |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v0.0.0-20260611092415-555255f7438e | Low risk | 0 | 2026-06-13 |
v0.0.0-20260609210751-cd1e39201697 | Low risk | 0 | 2026-06-11 |
v0.0.0-20260608214720-9ab0d937a58b | Low risk | 0 | 2026-06-10 |
v0.0.0-20260604231049-79b91b3d1c4f | Low risk | 0 | 2026-06-06 |
v0.0.0-20260604000217-49f85f000cdd | Low risk | 0 | 2026-06-05 |
v0.0.0-20260602053106-0acabcbe916a | Low risk | 0 | 2026-06-03 |
v0.0.0-20260529154125-a13147064073 | Review | 12 | 2026-05-31 |
v0.0.0-20260527215735-2d26820e638a | Review | 12 | 2026-05-29 |
Block this in CI
pkgradar gate --ecosystem go github.com/google/go-tpm-tools/[email protected]