PkgRadar

Go modules · proxy.golang.org

github.com/orneryd/nornicdb

Remote Payload: matched "cUrl "

Why PkgRadar flagged v1.1.4

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · github.com/orneryd/[email protected]/apoc/load/load.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/orneryd/[email protected]/cmd/kmeans-test-data/main.go
mediumRemote Payloadmatched "cURL " · github.com/orneryd/[email protected]/cmd/swagger-ui/main.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.1.4High risk442026-06-02
v1.1.3Review442026-05-30
v1.1.3-0.20260528200024-4c1c4a1883a8Review442026-05-29
v1.0.43-0.20260418063926-adce4f9a9fc7Review442026-05-29

Block this in CI

PkgRadar gates github.com/orneryd/nornicdb (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/orneryd/[email protected]