PkgRadar

Go modules · proxy.golang.org

github.com/hoophq/hoop/gateway

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.0.0-20260610214214-e6e7f0577bfe

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/hoophq/hoop/[email protected]/agentcontroller/controller.go
mediumRemote Payloadmatched "cURL " · github.com/hoophq/hoop/[email protected]/api/apiroutes/auth.go
mediumRemote Payloadmatched "curl " · github.com/hoophq/hoop/[email protected]/api/connections/connection_credentials.go
mediumRemote Payloadmatched "cURL " · github.com/hoophq/hoop/[email protected]/api/mcpauth/verifier.go
mediumRemote Payloadmatched "curl " · github.com/hoophq/hoop/[email protected]/api/openapi/autogen/docs.go
mediumRemote Payloadmatched "cURL " · github.com/hoophq/hoop/[email protected]/api/openapi/types.go
mediumRemote Payloadmatched "cURL " · github.com/hoophq/hoop/[email protected]/api/orgs/orgkeys.go
mediumRemote Payloadmatched "cURL " · github.com/hoophq/hoop/[email protected]/api/serverconfig/misc.go
mediumRemote Payloadmatched "cURL " · github.com/hoophq/hoop/[email protected]/api/serverinfo/serverinfo.go
mediumRemote Payloadmatched "cURL " · github.com/hoophq/hoop/[email protected]/appconfig/appconfig.go
mediumRemote Payloadmatched "cURL " · github.com/hoophq/hoop/[email protected]/idp/core.go
mediumRemote Payloadmatched "cURL " · github.com/hoophq/hoop/[email protected]/idp/types/types.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260610214214-e6e7f0577bfeHigh risk1382026-06-11
v0.0.0-20260609123312-4f61b57d31e3High risk1382026-06-10
v0.0.0-20260608201551-91e6f4fba4efHigh risk1382026-06-09
v0.0.0-20260603191419-121f8379ea66High risk1382026-06-04
v0.0.0-20260529191213-67aafcf14c41Review1382026-05-30
v0.0.0-20260529185649-72c5570fbd5dReview1382026-05-30
v0.0.0-20260529180557-8d66e2d1e264Review1382026-05-30
v0.0.0-20260527190412-abdb9ad2861aHigh risk1332026-05-30
v0.0.0-20260528150208-7dc0cd56f73dReview1382026-05-30

Block this in CI

PkgRadar gates github.com/hoophq/hoop/gateway (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/hoophq/hoop/[email protected]