PkgRadar

Go modules · proxy.golang.org

github.com/guanshan/pi-go

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.78.0-go

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/guanshan/[email protected]/packages/coding-agent/migrations.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.78.0-goReview222026-06-04
v0.0.0-20260601052810-02430b730461Review222026-06-02
v0.0.0-20260601051244-935c625e8c8bReview222026-06-02
v0.0.0-20260601042905-0eb653d525f4Review222026-06-02
v0.0.0-20260601041230-de76dbf01578Review222026-06-02

Block this in CI

PkgRadar gates github.com/guanshan/pi-go (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/guanshan/[email protected]