PkgRadar

Go modules · proxy.golang.org

github.com/koduj-dev/docker-commander

Remote Payload: matched "cURL "

Why PkgRadar flagged v1.4.1

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/koduj-dev/[email protected]/cmd/dockercmd/main.go
mediumRemote Payloadmatched "cURL " · github.com/koduj-dev/[email protected]/internal/api/mcp_token_handlers.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.4.1Review242026-06-16
v1.4.0Review242026-06-16
v1.4.2Review242026-06-16
v1.4.4Review242026-06-16
v1.4.3Review242026-06-16
v1.3.1-0.20260608201504-6f2ec6d69ae8Low risk02026-06-09
v1.3.0Low risk02026-06-09
v1.2.0Low risk02026-06-06
v1.1.0Low risk02026-06-06
v1.0.1-0.20260602203202-85eaf7656069Low risk02026-06-04

Block this in CI

PkgRadar gates github.com/koduj-dev/docker-commander (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/koduj-dev/[email protected]