PkgRadar

Go modules · proxy.golang.org

github.com/malamtime/cli

Remote Payload: matched "curl "

Why PkgRadar flagged v0.1.86-0.20260613132541-a116c7b0f42e

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/malamtime/[email protected]/commands/daemon.install.go
mediumRemote Payloadmatched "curl " · github.com/malamtime/[email protected]/commands/hooks.install.go
mediumRemote Payloadmatched "curl " · github.com/malamtime/[email protected]/commands/update.go
mediumRemote Payloadmatched "cURL " · github.com/malamtime/[email protected]/model/shell.bash.go
mediumRemote Payloadmatched "Curl\n" · github.com/malamtime/[email protected]/model/updater.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.1.86-0.20260613132541-a116c7b0f42eHigh risk702026-06-14
v0.1.85High risk702026-06-14

Block this in CI

PkgRadar gates github.com/malamtime/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/malamtime/[email protected]