PkgRadar

Go modules · proxy.golang.org

github.com/palantir/conjure

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260528032442-70d0fffdfcd3

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/palantir/[email protected]/gradle/gradle-jdks-functions.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260615011356-3da00966673dLow risk02026-06-16
v0.0.0-20260614165508-bdbaacad5c89Low risk02026-06-16
v0.0.0-20260614045744-a0c24ec37341Low risk02026-06-15
v0.0.0-20260613213844-69dfa43fc7b7Low risk02026-06-14
v0.0.0-20260612193427-8c9380518826Low risk02026-06-13
v0.0.0-20260611202934-f957f611ab99Low risk02026-06-13
v0.0.0-20260610140846-f46781f192ccLow risk02026-06-11
v0.0.0-20260610002450-f100bff6d9a7Low risk02026-06-11
v0.0.0-20260529235246-dc840c388d02Low risk02026-05-31
v0.0.0-20260528032442-70d0fffdfcd3Review122026-05-29

Block this in CI

PkgRadar gates github.com/palantir/conjure (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/palantir/[email protected]