PkgRadar

Go modules · proxy.golang.org

github.com/kopw/sing-box_mod

Remote Payload: matched "wget "

Why PkgRadar flagged v0.0.0-20260528120109-657d2268e6af

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · github.com/kopw/[email protected]/.github/setup_go_for_windows7.sh
mediumRemote Payloadmatched "curl " · github.com/kopw/[email protected]/release/local/install_go.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20251202212447-8d054dcd8bfeLow risk02026-05-30
v0.0.0-20260529024846-3ab85c3b8229Low risk02026-05-30
v0.0.0-20260529015948-088080ce57bdLow risk02026-05-30
v0.0.0-20260528120109-657d2268e6afReview292026-05-29

Block this in CI

PkgRadar gates github.com/kopw/sing-box_mod (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/kopw/[email protected]