PkgRadar

Go modules · proxy.golang.org

github.com/mindersec/minder

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v0.0.0-20260529074101-4ea1aea8a17d

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/mindersec/[email protected]/internal/auth/keycloak/client/client.go
mediumRemote Payloadmatched "cUrl " · github.com/mindersec/[email protected]/cmd/server/app/serve.go
mediumRemote Payloadmatched "cUrl " · github.com/mindersec/[email protected]/internal/auth/keycloak/keycloak.go
mediumRemote Payloadmatched "curl " · github.com/mindersec/[email protected]/internal/engine/actions/alert/security_advisory/security_advisory.go
mediumRemote Payloadmatched "curl " · github.com/mindersec/[email protected]/internal/engine/actions/remediate/gh_branch_protect/gh_branch_protect.go
mediumRemote Payloadmatched "curl " · github.com/mindersec/[email protected]/internal/engine/actions/remediate/pull_request/pull_request.go
mediumRemote Payloadmatched "curl " · github.com/mindersec/[email protected]/internal/engine/actions/remediate/rest/rest.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260529074101-4ea1aea8a17dReview952026-05-30
v0.1.3-0.20260529063433-14b279a522caReview952026-05-30
v0.0.0-20260529063433-14b279a522caReview952026-05-30
v0.1.3-0.20260528210318-6a8895eec79fReview952026-05-30
v0.0.0-20260528210318-6a8895eec79fReview952026-05-30
v0.1.3-0.20260528133401-71a061f9ab60Review952026-05-29
v0.0.0-20260528133401-71a061f9ab60Review952026-05-29

Block this in CI

PkgRadar gates github.com/mindersec/minder (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/mindersec/[email protected]