PkgRadar

Go modules · proxy.golang.org

github.com/okteto/cnd

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260612143638-fdde5c44edd8

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/okteto/[email protected]/cmd/utils/upgrade.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/okteto/[email protected]/pkg/schema/schema.go
mediumRemote Payloadmatched "github.com/syncthing/syncthing/releases/download" · github.com/okteto/[email protected]/pkg/syncthing/install.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260612143638-fdde5c44edd8High risk362026-06-13
v0.0.0-20260611155101-bf27bf83f7eaHigh risk362026-06-12
v0.0.0-20260605130145-9506c7454029High risk362026-06-06
v0.0.0-20260601083731-bbf6fa69cb79High risk362026-06-02
v0.0.0-20260529140824-75d0521a4f17Review362026-05-31

Block this in CI

PkgRadar gates github.com/okteto/cnd (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/okteto/[email protected]
github.com/okteto/cnd — Go modules security scan | PkgRadar