PkgRadar

Go modules · proxy.golang.org

github.com/google/syzkaller

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v0.0.0-20260615072059-c700a26e3167

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/google/[email protected]/executor/gen_linux_amd64.go
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/google/[email protected]/executor/gen_linux_ppc64le.go
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/google/[email protected]/sys/fuchsia/init.go
mediumRemote Payloadmatched "cURL " · github.com/google/[email protected]/pkg/asset/backend_dummy.go
mediumRemote Payloadmatched "cURL " · github.com/google/[email protected]/pkg/asset/backend_gcs.go
mediumRemote Payloadmatched "cURL " · github.com/google/[email protected]/pkg/asset/storage.go
mediumRemote Payloadmatched "cURL " · github.com/google/[email protected]/pkg/gcs/gcs.go
mediumRemote Payloadmatched "curl " · github.com/google/[email protected]/pkg/vcs/fuchsia.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260615072059-c700a26e3167High risk1052026-06-16
v0.0.0-20260612145234-4f06757f683aHigh risk1052026-06-13
v0.0.0-20260612110543-7a10305784d4High risk1052026-06-13
v0.0.0-20260612105645-d1880c0fde55High risk1052026-06-13
v0.0.0-20260611142809-7bc2b845a2f0High risk1052026-06-12
v0.0.0-20260611141246-c2785bda6ac6High risk1052026-06-12
v0.0.0-20260610134809-416ea548b956High risk1052026-06-11
v0.0.0-20260610094555-f79bac11032aHigh risk1052026-06-11
v0.0.0-20260609100630-c36c07f6c1f2High risk1052026-06-10
v0.0.0-20260605090057-48b6c3fa84d5High risk1052026-06-06
v0.0.0-20260603150640-be4246033da2High risk1052026-06-04
v0.0.0-20260603134458-79fa8e14eab3High risk1052026-06-04
v0.0.0-20260603124911-08ab31164c55High risk1052026-06-04
v0.0.0-20260603101010-234057e589a0High risk1052026-06-04
v0.0.0-20260602165857-3c0d21318d6dHigh risk1052026-06-03
v0.0.0-20260601135111-1095583bae1dHigh risk1052026-06-02
v0.0.0-20260601120333-386cc6dacdf7High risk1052026-06-02
v0.0.0-20260601104422-1b6d1710d13bHigh risk1052026-06-02
v0.0.0-20260601072537-8d8eeb3a2696High risk1052026-06-02
v0.0.0-20260528083925-9a5a7e5e39ffHigh risk1052026-05-30
v0.0.0-20260528070023-2763dbe3babdHigh risk1052026-05-30
v0.0.0-20260529094533-6b4a844333e8Review1052026-05-30
v0.0.0-20260529055828-a3d70215e269Review1052026-05-30
v0.0.0-20260528201608-0fdf6192c4a4Review1052026-05-29
v0.0.0-20260528124923-789f4dd7b4faReview1052026-05-29

Block this in CI

PkgRadar gates github.com/google/syzkaller (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/google/[email protected]