PkgRadar

Go modules · proxy.golang.org

github.com/google/trillian

Remote Payload: matched "curl "

Why PkgRadar flagged v1.7.4-0.20260604130418-220b7243f129

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/google/[email protected]/go.mod
mediumRemote Payloadmatched "curl " · github.com/google/[email protected]/go.sum

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20180319121841-cf9cd7c39d38Low risk02026-06-10
v1.2.1-0.20190123071248-7553d5f5b4dcLow risk02026-06-08
v1.7.4-0.20260604130418-220b7243f129Review242026-06-08
v1.2.2-0.20190123071248-7553d5f5b4dcLow risk02026-06-08
v1.7.4-0.20260602161614-f8d287c95c29Review242026-06-04
v0.0.0-20170629173837-cb51ebb1a6deLow risk02026-06-03
v1.2.2-0.20190619133759-4511faac1a5cReview122026-05-29

Block this in CI

PkgRadar gates github.com/google/trillian (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/google/[email protected]