PkgRadar

Go modules · proxy.golang.org

github.com/hecatehq/hecate

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.1.0-alpha.39.0.20260603010456-aea9520ec296

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/hecatehq/[email protected]/cmd/hecate/runtime_state.go
mediumRemote Payloadmatched "curl " · github.com/hecatehq/[email protected]/internal/agentadapters/toolkind.go
mediumRemote Payloadmatched "cURL " · github.com/hecatehq/[email protected]/internal/config/config.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.1.0-alpha.39.0.20260603010456-aea9520ec296High risk362026-06-04
v0.1.0-alpha.39.0.20260601183335-d2b629ebe0faHigh risk362026-06-03
v0.1.0-alpha.45High risk362026-06-03
v0.1.0-alpha.39.0.20260530193656-a68441f6b84bHigh risk362026-05-31
v0.1.0-alpha.43High risk362026-05-31

Block this in CI

PkgRadar gates github.com/hecatehq/hecate (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/hecatehq/[email protected]