PkgRadar

Go modules · proxy.golang.org

github.com/hyperdxio/hyperdx

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260528113656-a44fa21b8757

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/hyperdxio/[email protected]/docker/hyperdx/entry.local.base.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260602182337-9119de5fbee8Low risk02026-06-03
v0.0.0-20260602180438-a19ba549495eLow risk02026-06-03
v0.0.0-20260602134820-9357642d4f0cLow risk02026-06-03
v0.0.0-20260601205828-6bd4c9e525e1Low risk02026-06-03
v0.0.0-20260601125519-2a68145635fcLow risk02026-06-02
v0.0.0-20260529231213-8e52cef41d37Low risk02026-05-31
v0.0.0-20260529134559-b8f51ed9e128Low risk02026-05-30
v0.0.0-20260528215155-33eac72d79d2Low risk02026-05-30
v0.0.0-20260528113656-a44fa21b8757Review122026-05-29

Block this in CI

PkgRadar gates github.com/hyperdxio/hyperdx (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/hyperdxio/[email protected]