PkgRadar

Go modules · proxy.golang.org

github.com/hduhelp/api_open_sdk

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260601125826-8e59d5e9944c

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/hduhelp/[email protected]/go.mod
mediumRemote Payloadmatched "curl " · github.com/hduhelp/[email protected]/go.sum
mediumRemote Payloadmatched "cUrl " · github.com/hduhelp/[email protected]/mq/notice.go
mediumRemote Payloadmatched "cUrl " · github.com/hduhelp/[email protected]/notify/notify.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260601125826-8e59d5e9944cHigh risk482026-06-02
v0.0.0-20260528072028-7503c5930ddcHigh risk482026-05-30

Block this in CI

PkgRadar gates github.com/hduhelp/api_open_sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/hduhelp/[email protected]