PkgRadar

Go modules · proxy.golang.org

github.com/kgateway-dev/kgateway/v2

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v2.4.0-alpha.1.0.20260615143756-aa26af9c19d4

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/kgateway-dev/kgateway/[email protected]/pkg/utils/filter_types/filter_types.go
mediumRemote Payloadmatched "curl\n\n" · github.com/kgateway-dev/kgateway/[email protected]/pkg/utils/requestutils/curl/native_request.go
mediumRemote Payloadmatched "curl\n\n" · github.com/kgateway-dev/kgateway/[email protected]/pkg/utils/requestutils/curl/option.go
mediumRemote Payloadmatched "curl\n\n" · github.com/kgateway-dev/kgateway/[email protected]/pkg/utils/requestutils/curl/request.go
mediumRemote Payloadmatched "curl\n\n" · github.com/kgateway-dev/kgateway/[email protected]/pkg/utils/requestutils/grpcurl/options.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v2.4.0-alpha.1.0.20260615143756-aa26af9c19d4High risk662026-06-16
v2.4.0-alpha.1.0.20260615141334-2cb4d02dcb17High risk662026-06-16
v2.2.6High risk662026-06-13
v2.3.3High risk662026-06-13
v2.3.3-0.20260612175222-96e1330f72b7High risk662026-06-13
v2.3.3-0.20260609220137-5ba104c12e2eHigh risk662026-06-13
v2.4.0-alpha.1.0.20260612011525-febc045a6d8cHigh risk662026-06-13
v2.4.0-alpha.1.0.20260612010412-28661f922f9fHigh risk662026-06-13
v2.4.0-alpha.1.0.20260611200448-15605735b8c1High risk662026-06-12
v2.4.0-alpha.1.0.20260611232705-aecb36470502High risk662026-06-12
v2.4.0-alpha.1.0.20260609015558-eeef0fb5e18dHigh risk662026-06-12
v2.4.0-alpha.1.0.20260611175610-e79b67c1d91aHigh risk662026-06-12
v2.4.0-alpha.1.0.20260611011926-04f708fbf909High risk662026-06-12
v2.4.0-alpha.1.0.20260609185639-d43d508d7f82High risk662026-06-11
v2.2.6-0.20260605185637-c44f6b6512d3High risk662026-06-06
v2.3.0-rc.1.0.20260605200842-6517af711610High risk662026-06-06
v2.3.0-rc.1.0.20260605190420-2e12323a918bHigh risk662026-06-06
v2.3.0-rc.1.0.20260605153317-b50b0084fbbdHigh risk662026-06-06
v2.2.5High risk662026-06-05
v2.3.0-rc.1.0.20260604204709-db7e3a917920High risk662026-06-05
v2.3.0-rc.1.0.20260604201820-3a8e6c8e03c0High risk662026-06-05
v2.3.0-rc.1.0.20260604190842-b5f8df370fa2High risk662026-06-05
v2.3.0-rc.1.0.20260604184650-34937344a29fHigh risk662026-06-05
v2.3.0-rc.1.0.20260604173345-5c74aba18285High risk662026-06-05
v2.3.0-rc.1.0.20260604183304-a57215ab6cbfHigh risk662026-06-05
v2.3.2High risk662026-06-05
v2.3.2-0.20260604154200-3dd44612a967High risk662026-06-05
v2.3.0-rc.1.0.20260604142359-57324af0a2faHigh risk662026-06-05
v2.3.0-rc.1.0.20260604140232-96403169afb6High risk662026-06-05
v2.3.0-rc.1.0.20260604113419-caf10aa05a0cHigh risk662026-06-05
v2.3.0-rc.1.0.20260604133003-e48a44e50a71High risk662026-06-05
v2.3.0-rc.1.0.20260603171924-71625f9a0890High risk662026-06-05
v2.3.0-rc.1.0.20260604012950-7aef62c832c5High risk662026-06-05
v2.3.0-rc.1.0.20260601161505-6b047a776610High risk662026-06-02

Block this in CI

PkgRadar gates github.com/kgateway-dev/kgateway/v2 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/kgateway-dev/kgateway/[email protected]