PkgRadar

Go modules · proxy.golang.org

github.com/jfrog/jfrog-cli-artifactory

Remote Payload: matched "curl\n\n"

Why PkgRadar flagged v0.8.1-0.20260616042325-c0a813006d5e

SeveritySignalEvidence
mediumRemote Payloadmatched "curl\n\n" · github.com/jfrog/[email protected]/artifactory/commands/curl/curl.go
mediumRemote Payloadmatched "Curl " · github.com/jfrog/[email protected]/cliutils/flagkit/flags.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.8.1-0.20260616042325-c0a813006d5eReview292026-06-17
v0.8.1-0.20260610074911-82ce7d90edbdReview292026-06-11
v0.8.1-0.20260609101705-321f68d15a6dReview292026-06-10
v0.8.1-0.20260605085015-2102264e1dddReview292026-06-08
v0.8.1-0.20260604083052-cc843d5d22c3Review292026-06-05
v0.8.1-0.20260604090426-c24f4507e1e6Review292026-06-05
v0.8.1-0.20260603051001-7fc8a5fa0aafReview292026-06-04
v0.8.1-0.20260601110159-16e27949b870Review292026-06-02
v0.8.1-0.20260528123948-61478692b94eReview292026-05-29
v0.8.1-0.20260528073225-e2d59f90c8c6Review442026-05-29

Block this in CI

PkgRadar gates github.com/jfrog/jfrog-cli-artifactory (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/jfrog/[email protected]