PkgRadar

Go modules · proxy.golang.org

github.com/iotexproject/iotex-core

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20220228183013-112ffe50bb38

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/iotexproject/[email protected]/ioctl/cmd/contract/contractprepare.go
mediumRemote Payloadmatched "curl " · github.com/iotexproject/[email protected]/ioctl/cmd/update/update.go
mediumRemote Payloadmatched "curl " · github.com/iotexproject/[email protected]/ioctl/newcmd/update/update.go
mediumRemote Payloadmatched "curl " · github.com/iotexproject/[email protected]/tools/ioctl/readme/docgen.go
mediumRemote Payloadmatched "curl " · github.com/iotexproject/[email protected]/tools/xctl/readme/docgen.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20220228183013-112ffe50bb38High risk502026-06-14
v0.0.0-20220228200208-a4e5e6a3a360High risk502026-06-14
v0.0.0-20220209185257-8cce51c4d253High risk502026-06-14

Block this in CI

PkgRadar gates github.com/iotexproject/iotex-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/iotexproject/[email protected]