PkgRadar

Go modules · proxy.golang.org

github.com/gravwell/gravwell/v3

Go Init Env Token Exfil: Go init() reads CI / npm / cloud env tokens AND has network/exec on the same scope — canonical credential-exfil shape.

Why PkgRadar flagged v3.8.81-0.20260608180655-634371bea2ef

SeveritySignalEvidence
highGo Init Env Token ExfilGo init() reads CI / npm / cloud env tokens AND has network/exec on the same scope — canonical credential-exfil shape. · github.com/gravwell/gravwell/[email protected]/ingest/processors/plugin/packages.go
highGo Init Env Token ExfilGo init() reads CI / npm / cloud env tokens AND has network/exec on the same scope — canonical credential-exfil shape. · github.com/gravwell/gravwell/[email protected]/ingest/processors/plugin/packages_windows.go
mediumRemote Payloadmatched "CUrl " · github.com/gravwell/gravwell/[email protected]/ingesters/HttpIngester/hec_config.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v3.8.81-0.20260608180655-634371bea2efHigh risk722026-06-11
v3.8.81-0.20260608174407-f9717feb71e4High risk722026-06-11
v3.8.81-0.20260604193904-d75b4888b97cHigh risk722026-06-09
v3.8.81-0.20260604192839-bd805bb2f2a7High risk722026-06-09
v3.8.81-0.20260603143352-8d61e7749e75High risk722026-06-04
v3.8.81-0.20260603142249-ec5844ec442dHigh risk722026-06-04
v3.8.81-0.20260603141333-be938d8705caHigh risk722026-06-04
v3.8.81-0.20260602195044-57bf9e99e63cHigh risk722026-06-03
v3.8.81-0.20260602174105-2c09fd11e36dHigh risk722026-06-03
v3.8.81-0.20260601204123-57104b398bd4High risk722026-06-02
v3.8.81-0.20260601202944-42e49d35c0a4High risk722026-06-02

Block this in CI

PkgRadar gates github.com/gravwell/gravwell/v3 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/gravwell/gravwell/[email protected]