PkgRadar

Go modules · proxy.golang.org

github.com/pedronis/snappy

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.0.0-20260605110015-190ec8d02e5c

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/pedronis/[email protected]/client/interfaces.go
mediumRemote Payloadmatched "cURL " · github.com/pedronis/[email protected]/cmd/snap/cmd_interface.go
mediumRemote Payloadmatched "cURL " · github.com/pedronis/[email protected]/daemon/api_json.go
mediumRemote Payloadmatched "cURL " · github.com/pedronis/[email protected]/interfaces/builtin/common.go
mediumRemote Payloadmatched "cURL " · github.com/pedronis/[email protected]/interfaces/core.go
mediumRemote Payloadmatched "cURL " · github.com/pedronis/[email protected]/interfaces/repo.go
mediumRemote Payloadmatched "cURL " · github.com/pedronis/[email protected]/overlord/devicestate/devicestatetest/gadget.go
mediumRemote Payloadmatched "cURL " · github.com/pedronis/[email protected]/overlord/devicestate/handlers_serial.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260605110015-190ec8d02e5cHigh risk1062026-06-07
v0.0.0-20260603072122-dd8e1b6e5e73High risk1062026-06-04
v0.0.0-20260529172857-76051e1a5f69High risk1062026-06-02
v0.0.0-20260529120630-bd4435630204Review1062026-05-30

Block this in CI

PkgRadar gates github.com/pedronis/snappy (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/pedronis/[email protected]