PkgRadar

Go modules · proxy.golang.org

github.com/johnny1110/evva

Remote Payload: matched "curl "

Why PkgRadar flagged v1.7.0-beta.1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/johnny1110/[email protected]/internal/agent/sysprompt/disk_tools_guide.go
mediumRemote Payloadmatched "curl " · github.com/johnny1110/[email protected]/pkg/tools/cron/cron.go
mediumRemote Payloadmatched "curl " · github.com/johnny1110/[email protected]/pkg/tools/util/json_query.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.7.0-beta.1High risk362026-06-12
v1.6.0-beta.2High risk362026-06-12
v1.6.0-beta.3High risk362026-06-12
v1.4.5-beta.1Review242026-06-12
v1.5.0-beta.2Review242026-06-12
v1.5.1-beta.2Review242026-06-12
v1.4.4-beta.1Review242026-06-12
v1.4.4Review242026-06-12
v1.4.3-beta.1Review242026-06-12
v1.4.4-0.20260608032639-06c47fe0dd60Review242026-06-09
v1.4.3Review242026-06-09
v1.3.0-beta.1Review242026-05-31
v1.0.0-beta.1Review242026-05-29
v0.2.9-alpha.4Review242026-05-29
v0.2.8-alpha-2Review242026-05-29
v0.2.8-alpha.6Review242026-05-29
v0.2.8-alpha.5Review242026-05-29
v0.2.8-alpha.4Review242026-05-29
v1.1.0-beta.1.0.20260525091300-60f326a4c8d5Review362026-05-29
v1.2.0-alpha.2Review362026-05-29

Block this in CI

PkgRadar gates github.com/johnny1110/evva (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/johnny1110/[email protected]