PkgRadar

Go modules · proxy.golang.org

github.com/podman-container-tools/buildah

Remote Payload: matched "curl "

Why PkgRadar flagged v1.7.3

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/podman-container-tools/[email protected]/add.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.44.1-0.20260611070006-03d961990f6bLow risk02026-06-12
v1.44.1-0.20260601204905-5b1b18eebdc2Low risk02026-06-02
v1.7.3Review122026-06-02
v1.7.1Review122026-06-02
v1.7.2Review122026-06-02
v1.8.0Review122026-06-02
v1.14.6Review122026-06-02
v1.11.1Review122026-06-02
v0.16.0Review122026-06-02
v1.8.1Review122026-06-02
v1.8.4Review122026-06-02

Block this in CI

PkgRadar gates github.com/podman-container-tools/buildah (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/podman-container-tools/[email protected]