PkgRadar

Go modules · proxy.golang.org

github.com/lumeraprotocol/lumera

Remote Payload: matched "cURL "

Why PkgRadar flagged v1.20.0-rc4

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/lumeraprotocol/[email protected]/testutil/jsonrpc/jsonrpc.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/lumeraprotocol/[email protected]/tools/openrpcgen/main.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.20.0-rc4Review242026-06-12
v0.0.0-20260611205218-271cafe6a9ffReview242026-06-12
v1.20.0-rc2.0.20260608203016-dc4f94661e8eReview242026-06-10
v0.0.0-20260608203016-dc4f94661e8eReview242026-06-10
v1.20.0-rc2.0.20260603164056-a4f5f8c1928cReview242026-06-05
v0.0.0-20260603164056-a4f5f8c1928cReview242026-06-04
v1.11.2-0.20260414111336-a484d1fa1fd5Low risk02026-06-03
v1.20.0-rc2.0.20260601202744-26ab53fc3175Review242026-06-03
v1.11.2-0.20260413115024-f7d6f4a85625Low risk02026-05-29

Block this in CI

PkgRadar gates github.com/lumeraprotocol/lumera (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/lumeraprotocol/[email protected]