PkgRadar

Go modules · proxy.golang.org

github.com/projectsveltos/cluster-api-feature-manager

Remote Payload: matched "curl "

Why PkgRadar flagged v0.1.0-alpha.0.20221001212826-a9c1cd621a32

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/projectsveltos/cluster-api-feature-manager@v0.1.0-alpha.0.20221001212826-a9c1cd621a32/go.sum

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260611093205-4ae849a51567Low risk02026-06-12
v0.1.0-alpha.0.20221001212826-a9c1cd621a32Review122026-06-12
v1.11.1Low risk02026-06-12
v1.11.0Low risk02026-06-11
v0.0.0-20260610054824-daf7b131036eLow risk02026-06-11
v1.10.1-0.20260604131817-9834cc9d6611Low risk02026-06-05
v0.0.0-20260604131817-9834cc9d6611Low risk02026-06-05
v1.10.1-0.20260601155128-1b53d7e6c13bLow risk02026-06-03
v0.0.0-20260601155128-1b53d7e6c13bLow risk02026-06-03
v1.10.1-0.20260530102009-9011f39220b1Low risk02026-06-01

Block this in CI

PkgRadar gates github.com/projectsveltos/cluster-api-feature-manager (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/projectsveltos/cluster-api-feature-manager@v0.1.0-alpha.0.20221001212826-a9c1cd621a32