PkgRadar

Go modules · proxy.golang.org

github.com/jeffail/benthos/v4

Remote Payload: matched "github.com/build-trust/ockam/releases/download"

Why PkgRadar flagged v4.96.1

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/build-trust/ockam/releases/download" · github.com/jeffail/benthos/[email protected]/internal/impl/ockam/command.go
mediumRemote Payloadmatched "github.com/ollama/ollama/releases/download" · github.com/jeffail/benthos/[email protected]/internal/impl/ollama/subprocess_unix.go
mediumRemote Payloadmatched "cURL " · github.com/jeffail/benthos/[email protected]/internal/impl/otlp/input_http.go
mediumRemote Payloadmatched "cURL " · github.com/jeffail/benthos/[email protected]/internal/impl/redpanda/migrator/migrator_schema_registry.go
mediumRemote Payloadmatched "curl " · github.com/jeffail/benthos/[email protected]/internal/impl/snowflake/output_snowflake_put.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v4.96.1High risk832026-06-14
v4.96.0High risk832026-06-12
v4.95.1-0.20260605101924-9eb5e70b3d22High risk832026-06-06
v4.95.0High risk832026-06-06
v4.94.2-0.20260602140305-7057e7ce8280High risk832026-06-04
v4.94.2-0.20260529165413-6b47e2e38b52Review832026-05-30
v4.94.1Review832026-05-30
v4.94.1-0.20260528235937-5e98dd33b76eReview832026-05-30
v4.94.0Review832026-05-30

Block this in CI

PkgRadar gates github.com/jeffail/benthos/v4 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/jeffail/benthos/[email protected]