PkgRadar

Go modules · proxy.golang.org

github.com/google/go-tpm-tools/verifier

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260529154125-a13147064073

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/google/go-tpm-tools/[email protected]/go.sum

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260611092415-555255f7438eLow risk02026-06-13
v0.0.0-20260609210751-cd1e39201697Low risk02026-06-11
v0.0.0-20260608214720-9ab0d937a58bLow risk02026-06-10
v0.0.0-20260604231049-79b91b3d1c4fLow risk02026-06-06
v0.0.0-20260604000217-49f85f000cddLow risk02026-06-05
v0.0.0-20260602053106-0acabcbe916aLow risk02026-06-03
v0.0.0-20260529154125-a13147064073Review122026-05-31
v0.0.0-20260527215735-2d26820e638aReview122026-05-29

Block this in CI

PkgRadar gates github.com/google/go-tpm-tools/verifier (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/google/go-tpm-tools/[email protected]