PkgRadar

Go modules · proxy.golang.org

github.com/heroku/heroku-cli

Remote Payload: matched "curl "

Why PkgRadar flagged v11.4.1-0.20260527155031-355113e8253b+incompatible

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/heroku/[email protected]+incompatible/install-standalone.sh
mediumRemote Payloadmatched "curl " · github.com/heroku/[email protected]+incompatible/install-ubuntu.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v11.5.1-0.20260615194817-ad0466e1512b+incompatibleLow risk02026-06-17
v11.6.0-beta.0+incompatibleLow risk02026-06-17
v11.5.0+incompatibleLow risk02026-06-13
v11.5.0-alpha.6+incompatibleLow risk02026-06-12
v11.5.0-alpha.8+incompatibleLow risk02026-06-12
v11.5.0-alpha.5+incompatibleLow risk02026-06-12
v11.4.1-0.20260527155031-355113e8253b+incompatibleReview242026-05-29
v11.4.1-beta.0+incompatibleReview242026-05-29

Block this in CI

PkgRadar gates github.com/heroku/heroku-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/heroku/[email protected]+incompatible