PkgRadar

Go modules · proxy.golang.org

github.com/hobu/usgs-lidar

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260527165701-96e14869fcc3

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/hobu/[email protected]/lambda/test-lambda-proxy.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260614162419-d6c9c2e4b460Low risk02026-06-15
v0.0.0-20260613162130-300a0a2def2eLow risk02026-06-14
v0.0.0-20260611170824-a62cabc5af3aLow risk02026-06-12
v0.0.0-20260610165535-0652f034377cLow risk02026-06-11
v0.0.0-20260609164732-58449a3f938aLow risk02026-06-11
v0.0.0-20260608170317-5e44599ce95eLow risk02026-06-09
v0.0.0-20260607162154-499f74a40b15Low risk02026-06-08
v0.0.0-20260606161928-4f234b872b6dLow risk02026-06-07
v0.0.0-20260605164622-cd2b1d4330eaLow risk02026-06-06
v0.0.0-20260604165246-731c6fb509bfLow risk02026-06-05
v0.0.0-20260603173441-ee064a0b0467Low risk02026-06-04
v0.0.0-20260602172245-173b54e45cdfLow risk02026-06-04
v0.0.0-20260601175134-baaa038e74a2Low risk02026-06-02
v0.0.0-20260531162133-a72e4e1d3fe9Low risk02026-06-02
v0.0.0-20260530161856-417df83d2004Low risk02026-06-01
v0.0.0-20260529170328-06e088e11941Low risk02026-05-31
v0.0.0-20260528170828-89f7567a701aLow risk02026-05-29
v0.0.0-20260527165701-96e14869fcc3Review122026-05-29

Block this in CI

PkgRadar gates github.com/hobu/usgs-lidar (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/hobu/[email protected]