PkgRadar

Go modules · proxy.golang.org

github.com/mrz1836/go-mage

Remote Payload: matched "curl "

Why PkgRadar flagged v1.24.1-0.20260531041056-2aa03295e3b2

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/mrz1836/[email protected]/pkg/mage/agentos.go
mediumRemote Payloadmatched "Curl " · github.com/mrz1836/[email protected]/pkg/mage/constants.go
mediumRemote Payloadmatched "curl " · github.com/mrz1836/[email protected]/pkg/mage/lint.go
mediumRemote Payloadmatched "curl " · github.com/mrz1836/[email protected]/pkg/mage/speckit.go
mediumRemote Payloadmatched "Curl " · github.com/mrz1836/[email protected]/pkg/mage/speckit_release.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.24.1-0.20260531041056-2aa03295e3b2High risk602026-06-04
v1.22.1High risk602026-06-04
v1.22.0High risk602026-06-04
v1.23.1-0.20260526221159-4bbdb3f714dcReview602026-05-31
v1.23.0Review602026-05-31

Block this in CI

PkgRadar gates github.com/mrz1836/go-mage (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/mrz1836/[email protected]