PkgRadar

Go modules · proxy.golang.org

github.com/openshift/ci-tools

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.0.0-20260616192917-c9af0327d90a

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/openshift/[email protected]/cmd/payload-testing-ui/server.go
mediumRemote Payloadmatched "curl " · github.com/openshift/[email protected]/go.mod
mediumRemote Payloadmatched "curl " · github.com/openshift/[email protected]/go.sum
mediumRemote Payloadmatched "cURL " · github.com/openshift/[email protected]/pkg/html/html.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260616192917-c9af0327d90aHigh risk532026-06-18
v0.0.0-20260616115532-98989ede9354High risk532026-06-17
v0.0.0-20190529112909-973a44ab88b1Low risk02026-06-14
v0.0.0-20240531153510-7cc8b43876bcHigh risk652026-06-14
v0.0.0-20260611041257-4b8b1c45b09aHigh risk532026-06-12
v0.0.0-20260610170129-248388464556High risk532026-06-11
v0.0.0-20260610135852-3a61181368cdHigh risk532026-06-11
v0.0.0-20260608115726-67de89a978b0High risk532026-06-09
v0.0.0-20260605150033-83dc036c2e5dHigh risk532026-06-06
v0.0.0-20260604211154-483527bf8a89High risk532026-06-06
v0.0.0-20260604104139-4f3c20255c2bHigh risk532026-06-05
v0.0.0-20260603225148-4788bfa6b085High risk532026-06-04
v0.0.0-20260603190624-f99d12922bf6High risk532026-06-04
v0.0.0-20260602122835-f488302862c5High risk532026-06-03
v0.0.0-20260601173009-8c13338c6e8dHigh risk532026-06-02
v0.0.0-20260601021347-3fcf3b43f1c8High risk532026-06-02
v0.0.0-20260530110011-f133840a369fHigh risk532026-05-31
v0.0.0-20260529170018-e89b8e95a9f6Review532026-05-30
v0.0.0-20260528180449-7b6e7b89f436Review532026-05-29
v0.0.0-20260528163223-fa6b50c011e7Review532026-05-29
v0.0.0-20260528134204-b7957c491706Review532026-05-29

Block this in CI

PkgRadar gates github.com/openshift/ci-tools (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/openshift/[email protected]