PkgRadar

Go modules · proxy.golang.org

github.com/opensin-code/sin-code

Remote Payload: matched "curl "

Why PkgRadar flagged v1.9.1-0.20260616214807-7e49eaf8231a

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/opensin-code/[email protected]/cmd/sin-code/internal/codegraph/codegraph.go
mediumRemote Payloadmatched "curl " · github.com/opensin-code/[email protected]/cmd/sin-code/internal/rtk/rtk.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.9.1-0.20260616214807-7e49eaf8231aReview292026-06-17
v1.0.8Review52026-06-17
v1.3.0Low risk02026-06-17
v1.7.0Low risk02026-06-17
v1.0.6-sin-codeReview52026-06-17
v1.9.1-0.20260616175353-6aeb7427421eReview292026-06-17
v0.3.9Low risk02026-06-17
v1.0.4-sin-codeReview52026-06-17
v0.7.0Low risk02026-06-17
v0.8.1Low risk02026-06-17
v1.8.0Review52026-06-17
v0.1.1Review52026-06-17
v0.6.3Low risk02026-06-17
v1.0.7Review52026-06-17
v1.0.1-sin-codeLow risk02026-06-17
v1.1.0Review52026-06-17
v1.8.1Review52026-06-17
v1.0.5-sin-codeReview52026-06-17
v0.3.1Low risk02026-06-17
v1.0.0-sin-codeLow risk02026-06-17
v0.1.0Review52026-06-17
v1.9.1-0.20260616163149-d393f8e1862bReview292026-06-17
v0.5.1Low risk02026-06-17
v0.6.5Low risk02026-06-17
v0.9.0Low risk02026-06-17
v0.4.4Low risk02026-06-17
v0.3.3Low risk02026-06-17
v0.1.2Review52026-06-17
v1.0.0Low risk02026-06-17
v0.8.0Low risk02026-06-17
v0.4.3Low risk02026-06-17
v0.3.8Low risk02026-06-17
v0.3.0Low risk02026-06-17
v0.4.5Low risk02026-06-17

Block this in CI

PkgRadar gates github.com/opensin-code/sin-code (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/opensin-code/[email protected]