PkgRadar

Go modules · proxy.golang.org

github.com/openshift/sippy

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.0.0-20260615224602-a8f11da6deaf

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/openshift/[email protected]/pkg/dataloader/releaseloader/releasesync.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260615224602-a8f11da6deafReview262026-06-16
v0.0.0-20260615215350-dbfb2742b253Review262026-06-16
v0.0.0-20260615114033-d362395b677cReview262026-06-16
v0.0.0-20260614224946-82f337cd3ee8Review262026-06-15
v0.0.0-20260614104053-c2e72ad14af9Review262026-06-15
v0.0.0-20260614005111-82076f28075cReview262026-06-15
v0.0.0-20260613152639-727b16f4b2dbReview262026-06-14
v0.0.0-20260612223816-af8b7787a6a3Review262026-06-13
v0.0.0-20260611222959-aa8d3ef378b1Review262026-06-13
v0.0.0-20260610181352-f9c9ec236bd8Review262026-06-11
v0.0.0-20260610001714-29f812e90680Review262026-06-11
v0.0.0-20260609161155-412e8dcd025dReview262026-06-10
v0.0.0-20260609103059-f6aa5f40945bReview262026-06-10
v0.0.0-20260609013430-9a1c9dafad11Review262026-06-10
v0.0.0-20260607103847-fb632c48fcecReview262026-06-08
v0.0.0-20260605224629-387c7efacab4Review262026-06-07
v0.0.0-20260601115909-fd633066ba2bReview262026-06-02
v0.0.0-20260528180449-f190e5b2249eReview262026-05-30
v0.0.0-20260528144905-ee7ddede74adReview262026-05-29
v0.0.0-20260527175250-273943955599Review262026-05-29

Block this in CI

PkgRadar gates github.com/openshift/sippy (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/openshift/[email protected]