PkgRadar

Go modules · proxy.golang.org

github.com/jkodroff/go-git/v5

Remote Payload: matched "curl "

Why PkgRadar flagged v5.14.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/jkodroff/go-git/[email protected]/blame.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v5.7.0Low risk02026-06-11
v5.14.0Review122026-06-11
v5.6.0Low risk02026-06-11
v5.17.0Review122026-06-11
v5.5.0Low risk02026-06-11
v5.16.3Review122026-06-11
v5.17.1Review122026-06-11
v5.8.0Review122026-06-11
v5.13.0Review122026-06-11
v5.19.0Review122026-06-11
v5.16.1Review122026-06-11
v5.10.0Review122026-06-11
v5.13.1Review122026-06-11
v5.0.0Low risk02026-06-11
v5.6.1Low risk02026-06-11
v5.12.0Review122026-06-11
v5.19.2-0.20260610220839-2af8e8c3bc9fReview122026-06-11
v5.11.0Review122026-06-11
v5.18.0Review122026-06-11

Block this in CI

PkgRadar gates github.com/jkodroff/go-git/v5 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/jkodroff/go-git/[email protected]