PkgRadar

Go modules · proxy.golang.org

github.com/phronesis-io/eigenflux

Remote Payload: matched "curl\n\n"

Why PkgRadar flagged v0.0.0-20260613172740-266fc0e7f498

SeveritySignalEvidence
mediumRemote Payloadmatched "curl\n\n" · github.com/phronesis-io/[email protected]/pkg/publicurl/resolve.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260613172740-266fc0e7f498Review122026-06-15
v0.0.0-20260612085749-81cb0f9dcc27Review122026-06-14
v0.0.0-20260609120307-816645d4f07dReview122026-06-10
v0.0.0-20260609110850-68853fb1f854Review122026-06-10
v0.0.0-20260605094617-46a44672cc78Review122026-06-07
v0.0.0-20260604143755-d2f347c0ada1Review122026-06-05
v0.0.0-20260604102543-8024bb878fbeReview122026-06-05
v0.0.0-20260604092859-79e3ebd61744Review122026-06-05
v0.0.0-20260604085619-48c52928f455Review122026-06-05
v0.0.0-20260604075124-f53d7457bb08Review122026-06-05
v0.0.0-20260601085427-c3f0717affd4Review122026-06-02
v0.0.0-20260529090006-25fb7e3fe6e7Review122026-05-31

Block this in CI

PkgRadar gates github.com/phronesis-io/eigenflux (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/phronesis-io/[email protected]