PkgRadar

Go modules · proxy.golang.org

github.com/os-artificer/ait

Remote Payload: matched "curl "

Why PkgRadar flagged v1.0.0-beta.1.0.20260609164158-9e8e4a091431

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/os-artificer/[email protected]/internal/ait/ai/mode/risk/constants.go
mediumRemote Payloadmatched "curl " · github.com/os-artificer/[email protected]/internal/pkg/ollama/setup_install.go
mediumRemote Payloadmatched "curl " · github.com/os-artificer/[email protected]/internal/pkg/ollama/setup_manual.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.0.0-beta.1.0.20260609164158-9e8e4a091431High risk612026-06-11
v1.0.0-beta.1.0.20260608154305-15d74b440e08High risk612026-06-10
v1.0.0-beta.1.0.20260607155236-aaf0ee24550eHigh risk612026-06-09
v1.0.0-beta.1High risk612026-06-07
v0.0.0-20260604151923-c58e7b029964High risk612026-06-07
v0.0.0-20260604042437-07ab1ca5b982High risk612026-06-05
v0.0.0-20260604014757-7f096be08738High risk612026-06-05
v0.0.0-20260602155944-43cc3677e590High risk612026-06-04
v0.0.0-20260602044416-5aba805cfbf7High risk612026-06-03
v0.0.0-20260531162328-ea70c760ad6eHigh risk612026-06-01
v0.0.0-20260531160121-54b40bed5a75High risk612026-06-01
v0.0.0-20260531160007-5a4ef7b5314aHigh risk612026-06-01
v0.0.0-20260531152950-40f5628a83f3High risk612026-06-01
v0.0.0-20260531075940-9f5352000e86High risk612026-06-01
v0.0.0-20260531074052-f613cd8afb1fHigh risk612026-06-01
v0.0.0-20260531071522-0ead7d31ff99High risk612026-06-01
v0.0.0-20260531055758-623c46eb6c11High risk612026-06-01
v0.0.0-20260531052723-ddf982f5bb33High risk612026-06-01
v0.0.0-20260530160607-9cf973143d9cHigh risk612026-06-01
v0.0.0-20260530144506-eca87ff91c41High risk612026-05-31
v0.0.0-20260527160158-2d025d0f451cHigh risk612026-05-30

Block this in CI

PkgRadar gates github.com/os-artificer/ait (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/os-artificer/[email protected]