PkgRadar

Go modules · proxy.golang.org

github.com/layertwo-labs/sidesail/sidechain-orchestrator

Remote Payload: matched "CURL\n\t"

Why PkgRadar flagged v0.0.0-20260608122131-75219b66abcf

SeveritySignalEvidence
mediumRemote Payloadmatched "CURL\n\t" · github.com/layertwo-labs/sidesail/[email protected]/api/orchestrator_handler.go
mediumRemote Payloadmatched "CURL " · github.com/layertwo-labs/sidesail/[email protected]/gen/orchestrator/v1/orchestrator.pb.go
mediumRemote Payloadmatched "Curl\n\t" · github.com/layertwo-labs/sidesail/[email protected]/reset.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260608122131-75219b66abcfHigh risk362026-06-09
v0.0.0-20260606194811-0e20a2f8545eHigh risk362026-06-08
v0.0.0-20260605165922-31fc539e9317High risk362026-06-06
v0.0.0-20260603202945-1d301784715cHigh risk362026-06-05
v0.0.0-20260603104631-048848ec966dHigh risk362026-06-04
v0.0.0-20260530184616-85080cef6a38Review242026-06-01
v0.0.0-20260529181007-2ae5ed5663a2Review242026-05-30
v0.0.0-20260528124050-5e05b8d8e1bbReview242026-05-30

Block this in CI

PkgRadar gates github.com/layertwo-labs/sidesail/sidechain-orchestrator (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/layertwo-labs/sidesail/[email protected]
github.com/layertwo-labs/sidesail/sidechain-orchestrator — Go modules security scan | PkgRadar