PkgRadar

Go modules · proxy.golang.org

github.com/picosh/pico

Remote Payload: matched "curl "

Why PkgRadar flagged v1.13.2-0.20260531140231-e8485481b90f

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/picosh/[email protected]/pkg/apps/pastes/api.go
mediumRemote Payloadmatched "curl " · github.com/picosh/[email protected]/pkg/apps/prose/api.go
mediumRemote Payloadmatched "curl " · github.com/picosh/[email protected]/pkg/filehandlers/imgs/handler.go
mediumRemote Payloadmatched "curl " · github.com/picosh/[email protected]/pkg/filehandlers/post_handler.go
mediumRemote Payloadmatched "curl " · github.com/picosh/[email protected]/pkg/shared/config.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.13.2-0.20260531140231-e8485481b90fHigh risk552026-06-06

Block this in CI

PkgRadar gates github.com/picosh/pico (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/picosh/[email protected]