PkgRadar

Go modules · proxy.golang.org

github.com/openclaw-rocks/k8s-operator

Remote Payload: matched "curl "

Why PkgRadar flagged v0.36.3-0.20260615170403-4adde0edd49d

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/openclaw-rocks/[email protected]/internal/resources/environment_skill.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.36.3-0.20260615170403-4adde0edd49dReview172026-06-17
v0.36.2Review172026-06-17
v0.36.1Review172026-06-10
v0.34.8Review172026-06-03
v0.34.8-0.20260601083354-af2d7614b512Review172026-06-03
v0.34.7Review172026-06-03
v0.34.6Review172026-06-02

Block this in CI

PkgRadar gates github.com/openclaw-rocks/k8s-operator (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/openclaw-rocks/[email protected]