PkgRadar

Go modules · proxy.golang.org

github.com/hidevopsio/hiboot

Remote Payload: matched "curl "

Why PkgRadar flagged v1.8.5-0.20260608102401-118a0f39ed9a

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/hidevopsio/[email protected]/go.mod
mediumRemote Payloadmatched "curl " · github.com/hidevopsio/[email protected]/go.sum
mediumRemote Payloadmatched "cURL " · github.com/hidevopsio/[email protected]/pkg/starter/swagger/info_builder.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.8.5-0.20260608102401-118a0f39ed9aHigh risk362026-06-09
v1.8.5-0.20260608003159-f580dafa8cd2High risk362026-06-08
v1.8.5-0.20260530054313-e9d99499ba7cReview362026-05-31
v1.8.5-0.20260530041948-e6aa0a18d993Review362026-05-31

Block this in CI

PkgRadar gates github.com/hidevopsio/hiboot (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/hidevopsio/[email protected]