PkgRadar

Go modules · proxy.golang.org

github.com/rClone/rclone

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v1.74.1-0.20260530165849-74436281edab

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/rclone/[email protected]/vfs/vfs.go
mediumRemote Payloadmatched "cURL " · github.com/rclone/[email protected]/backend/azurefiles/azurefiles.go
mediumRemote Payloadmatched "cURL " · github.com/rclone/[email protected]/backend/ulozto/api/types.go
mediumRemote Payloadmatched "cURL " · github.com/rclone/[email protected]/backend/yandex/api/types.go
mediumRemote Payloadmatched "cURL " · github.com/rclone/[email protected]/backend/yandex/yandex.go
mediumRemote Payloadmatched "cURL " · github.com/rclone/[email protected]/cmd/gui/gui.go
mediumRemote Payloadmatched "Curl\n" · github.com/rclone/[email protected]/fs/dump.go
mediumRemote Payloadmatched "cURL\n\t" · github.com/rclone/[email protected]/lib/http/context.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.74.1-0.20260530165849-74436281edabHigh risk1192026-05-31
v1.74.1High risk1192026-05-31
v1.74.2High risk1192026-05-31

Block this in CI

PkgRadar gates github.com/rClone/rclone (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/rClone/[email protected]