PkgRadar

Go modules · proxy.golang.org

github.com/palantir/gradle-git-version

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260528032021-8e1eb63d8874

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/palantir/[email protected]/gradle/gradle-jdks-functions.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260615005020-8519c8a99efdLow risk02026-06-16
v0.0.0-20260614220845-ba478332b88fLow risk02026-06-15
v0.0.0-20260614123404-4bff9c439721Low risk02026-06-15
v0.0.0-20260613003025-a594b76e18a7Low risk02026-06-14
v0.0.0-20260528032021-8e1eb63d8874Review122026-05-29

Block this in CI

PkgRadar gates github.com/palantir/gradle-git-version (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/palantir/[email protected]