PkgRadar

Go modules · proxy.golang.org

github.com/mkaczanowski/packer

Remote Payload: matched "curl "

Why PkgRadar flagged v1.4.6-0.20191211142523-f1765dfd798d

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/mkaczanowski/[email protected]/builder/googlecompute/startup.go
mediumRemote Payloadmatched "curl " · github.com/mkaczanowski/[email protected]/builder/oracle/classic/pv_config.go
mediumRemote Payloadmatched "curl " · github.com/mkaczanowski/[email protected]/builder/osc/chroot/step_vm_info.go
mediumRemote Payloadmatched "curl " · github.com/mkaczanowski/[email protected]/post-processor/googlecompute-export/startup.go
mediumRemote Payloadmatched "curl " · github.com/mkaczanowski/[email protected]/provisioner/chef-client/provisioner.go
mediumRemote Payloadmatched "curl " · github.com/mkaczanowski/[email protected]/provisioner/chef-solo/provisioner.go
mediumRemote Payloadmatched "curl " · github.com/mkaczanowski/[email protected]/provisioner/converge/provisioner.go
mediumRemote Payloadmatched "curl " · github.com/mkaczanowski/[email protected]/provisioner/salt-masterless/provisioner.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.4.6-0.20191211142523-f1765dfd798dHigh risk1182026-06-03
v0.3.10High risk482026-06-03
v0.8.0High risk362026-06-03
v0.8.3High risk362026-06-03
v0.1.0Review242026-06-03
v0.1.4Review292026-06-03
v0.3.0High risk362026-06-03
v0.2.0Review242026-06-03
v0.7.2High risk602026-06-03
v0.3.3High risk362026-06-03
v0.4.1High risk482026-06-03
v0.3.4High risk362026-06-03
v0.5.0High risk482026-06-03
v0.2.3High risk362026-06-03
v0.8.6High risk362026-06-03
v1.4.5High risk1182026-06-03

Block this in CI

PkgRadar gates github.com/mkaczanowski/packer (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/mkaczanowski/[email protected]