PkgRadar

Go modules · proxy.golang.org

github.com/hanzoai/commerce

Remote Payload: matched "cUrl "

Why PkgRadar flagged v1.42.23

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · github.com/hanzoai/[email protected]/config/config.go
mediumRemote Payloadmatched "cUrl " · github.com/hanzoai/[email protected]/config/development.go
mediumRemote Payloadmatched "cUrl " · github.com/hanzoai/[email protected]/config/production.go
mediumRemote Payloadmatched "cUrl " · github.com/hanzoai/[email protected]/config/sandbox.go
mediumRemote Payloadmatched "cUrl " · github.com/hanzoai/[email protected]/config/staging.go
mediumRemote Payloadmatched "cUrl " · github.com/hanzoai/[email protected]/config/test.go
mediumRemote Payloadmatched "CURL " · github.com/hanzoai/[email protected]/payment/providers/solanapay/solanapay.go
mediumRemote Payloadmatched "cURL " · github.com/hanzoai/[email protected]/thirdparty/mpc/processor.go
mediumRemote Payloadmatched "cUrl\n\t" · github.com/hanzoai/[email protected]/util/template/template.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.42.23High risk1012026-06-09
v1.42.20High risk1012026-06-08
v1.42.19High risk1012026-06-08
v1.42.17High risk1012026-06-08
v1.42.18High risk1012026-06-08
v1.42.15High risk1012026-06-08
v1.42.16High risk1012026-06-08
v1.42.12High risk1112026-06-08
v1.42.14High risk1012026-06-08
v1.42.22-0.20260607202303-24f06a0cf8e4High risk1012026-06-08
v1.42.13High risk1012026-06-08
v1.42.9High risk1112026-06-08
v1.42.11High risk1112026-06-08
v1.42.8High risk1112026-06-08
v1.42.6High risk1112026-06-08
v1.42.10High risk1112026-06-08
v1.42.21High risk1012026-06-08
v1.42.7High risk1112026-06-08

Block this in CI

PkgRadar gates github.com/hanzoai/commerce (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/hanzoai/[email protected]