PkgRadar

Go modules · proxy.golang.org

github.com/openclaw/crabbox

Remote Payload: matched "curl "

Why PkgRadar flagged v0.32.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/openclaw/[email protected]/internal/cli/actions.go
mediumRemote Payloadmatched "github.com/git-for-windows/git/releases/download" · github.com/openclaw/[email protected]/internal/cli/bootstrap.go
mediumRemote Payloadmatched "curl " · github.com/openclaw/[email protected]/internal/cli/code.go
mediumRemote Payloadmatched "curl " · github.com/openclaw/[email protected]/internal/cli/coordinator.go
mediumRemote Payloadmatched "curl " · github.com/openclaw/[email protected]/internal/cli/doctor.go
mediumRemote Payloadmatched "curl " · github.com/openclaw/[email protected]/internal/cli/network.go
mediumRemote Payloadmatched "curl " · github.com/openclaw/[email protected]/internal/cli/parallels.go
mediumRemote Payloadmatched "curl " · github.com/openclaw/[email protected]/internal/cli/proxmox.go
mediumRemote Payloadmatched "curl " · github.com/openclaw/[email protected]/internal/providers/applecontainer/backend.go
mediumRemote Payloadmatched "github.com/git-for-windows/git/releases/download" · github.com/openclaw/[email protected]/internal/providers/hyperv/backend.go
mediumRemote Payloadmatched "curl " · github.com/openclaw/[email protected]/internal/providers/localcontainer/backend.go
mediumRemote Payloadmatched "curl " · github.com/openclaw/[email protected]/internal/providers/xcpng/cloudinit.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.32.0High risk1042026-06-17
v0.31.1-0.20260615103306-4fccd01713b3High risk1042026-06-16
v0.31.1-0.20260614110439-d3d1891aafa7High risk1042026-06-15
v0.31.0High risk1042026-06-15
v0.30.1-0.20260613153613-57e1113dfcdaHigh risk1042026-06-14
v0.30.0High risk1042026-06-14
v0.29.1-0.20260612163514-8ab288de0971High risk1042026-06-13
v0.28.0High risk872026-06-11
v0.27.1-0.20260609165848-0c610c664b7aHigh risk872026-06-10
v0.27.0High risk872026-06-10
v0.26.1High risk872026-06-10
v0.26.1-0.20260602133950-c6fef7c90b41High risk872026-06-03
v0.26.0High risk872026-06-03
v0.25.1-0.20260601221225-d91cffb674daHigh risk872026-06-03
v0.25.0High risk872026-06-03
v0.24.1-0.20260531135526-a1c6cc732a57High risk872026-06-01
v0.24.0High risk822026-06-01
v0.23.0High risk822026-05-31
v0.22.1Review822026-05-30
v0.22.1-0.20260529015123-9eea817b36b2Review822026-05-30
v0.22.0Review822026-05-30
v0.21.1-0.20260528194741-81cdb0218a3cReview822026-05-29
v0.8.1-0.20260509223907-6b07193fb567Review672026-05-29

Block this in CI

PkgRadar gates github.com/openclaw/crabbox (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/openclaw/[email protected]