PkgRadar

Go modules · proxy.golang.org

github.com/junyu-peng/katalyst-core

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.5.34-0.20260610035147-38ba470a6970

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/junyu-peng/[email protected]/pkg/custom-metric/collector/prometheus/scrape.go
mediumRemote Payloadmatched "cURL " · github.com/junyu-peng/[email protected]/pkg/custom-metric/store/remote/sharding.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.5.34-0.20260610035147-38ba470a6970Review242026-06-11
v0.5.34-0.20260610031453-dc84f1a35da9Review242026-06-11
v0.5.34-0.20260610023622-0f3249c8b7b8Review242026-06-11
v0.5.34-0.20260610030547-2fdd414cf84cReview242026-06-11
v0.5.34-0.20260605083416-8f9816a8d275Review242026-06-06
v0.5.34-0.20260605070817-f3983a8b41f5Review242026-06-06
v0.5.34-0.20260603134844-674eca905337Review242026-06-04
v0.5.34-0.20260602071454-361a476d4a15Review242026-06-03
v0.5.34-0.20260601085857-e8c3a5ded47dReview242026-06-02
v0.5.34-0.20260528080532-002341d5d9afReview242026-05-30
v0.5.34-0.20260529072518-f29821cee39fReview242026-05-30

Block this in CI

PkgRadar gates github.com/junyu-peng/katalyst-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/junyu-peng/[email protected]