PkgRadar

Go modules · proxy.golang.org

github.com/pingcap/tiDB

Remote Payload: matched "CURL "

Why PkgRadar flagged v1.0.5

SeveritySignalEvidence
mediumRemote Payloadmatched "CURL " · github.com/pingcap/[email protected]/_vendor/src/github.com/cznic/parser/yacc/parser.go
mediumRemote Payloadmatched "wGet\n\t\t" · github.com/pingcap/[email protected]/store/tikv/mock-tikv/rpc.go
mediumRemote Payloadmatched "wGet\n\t" · github.com/pingcap/[email protected]/store/tikv/rawkv.go
mediumRemote Payloadmatched "wGet " · github.com/pingcap/[email protected]/store/tikv/tikvrpc/tikvrpc.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.0.5High risk482026-06-14
v1.0.0High risk482026-06-14
v1.0.6High risk482026-06-14
v1.1.0-alphaHigh risk482026-06-14
v1.1.0-alpha.1High risk362026-06-14
v1.0.7High risk482026-06-14
v1.0.9High risk482026-06-14

Block this in CI

PkgRadar gates github.com/pingcap/tiDB (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/pingcap/[email protected]