PkgRadar

Go modules · proxy.golang.org

github.com/hashicorp/vault

Remote Payload: matched "cURL "

Why PkgRadar flagged v1.2.1-0.20260602200223-c5372ddfb782

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/hashicorp/[email protected]/command/base.go
mediumRemote Payloadmatched "cURL " · github.com/hashicorp/[email protected]/command/main.go
mediumRemote Payloadmatched "wget " · github.com/hashicorp/[email protected]/helper/testhelpers/testimages/hsm.go
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/hashicorp/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.2.1-0.20260602200223-c5372ddfb782High risk612026-06-03
v1.2.1-0.20260602163050-570025930271High risk612026-06-03
v1.2.1-0.20260601194205-0bebe0058dddHigh risk612026-06-02
v0.0.0-20260601194205-0bebe0058dddHigh risk612026-06-02
v1.2.1-0.20260601175850-571fc5cd3b81High risk612026-06-02
v0.0.0-20260601175850-571fc5cd3b81High risk612026-06-02
v1.2.1-0.20260601125215-17382ef05fd0High risk612026-06-02
v0.0.0-20160929154348-66c9302f1776Review182026-05-31
v0.0.0-20260529151944-063838867567Review612026-05-30
v1.2.1-0.20260528180116-a2ecfee8ab85Review612026-05-29
v0.0.0-20260528180116-a2ecfee8ab85Review612026-05-29
v1.2.1-0.20260528162551-b6c795ccbd1eReview612026-05-29

Block this in CI

PkgRadar gates github.com/hashicorp/vault (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/hashicorp/[email protected]