PkgRadar

Go modules · proxy.golang.org

github.com/jpvelasco/juggernaut

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260613170743-29717a413758

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/jpvelasco/[email protected]/cmd/apply.go
mediumRemote Payloadmatched "curl " · github.com/jpvelasco/[email protected]/cmd/migrate.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v2.1.2+incompatibleLow risk02026-06-14
v2.1.0+incompatibleLow risk02026-06-14
v3.2.2+incompatibleLow risk02026-06-14
v2.0.0+incompatibleLow risk02026-06-14
v2.3.0+incompatibleLow risk02026-06-14
v2.1.1+incompatibleLow risk02026-06-14
v2.2.5-rc.1+incompatibleLow risk02026-06-14
v3.0.0+incompatibleLow risk02026-06-14
v2.3.1+incompatibleLow risk02026-06-14
v2.2.0+incompatibleLow risk02026-06-14
v2.2.4-rc.2+incompatibleLow risk02026-06-14
v3.0.8+incompatibleLow risk02026-06-14
v3.1.0+incompatibleLow risk02026-06-14
v3.2.0+incompatibleLow risk02026-06-14
v3.0.1+incompatibleLow risk02026-06-14
v2.1.3+incompatibleLow risk02026-06-14
v2.2.5+incompatibleLow risk02026-06-14
v2.2.4+incompatibleLow risk02026-06-14
v2.2.4-rc.1+incompatibleLow risk02026-06-14
v3.0.3+incompatibleLow risk02026-06-14
v3.1.1+incompatibleLow risk02026-06-14
v2.2.1+incompatibleLow risk02026-06-14
v0.0.0-20260613170743-29717a413758Review242026-06-14
v3.2.3+incompatibleLow risk02026-06-14

Block this in CI

PkgRadar gates github.com/jpvelasco/juggernaut (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/jpvelasco/[email protected]