PkgRadar

Go modules · proxy.golang.org

github.com/rancherfederal/k3ama

Remote Payload: matched "cUrl "

Why PkgRadar flagged v1.1.0-rc.10

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · github.com/rancherfederal/[email protected]/pkg/artifacts/file/getter/getter.go
mediumRemote Payloadmatched "github.com/k3s-io/k3s/releases/download" · github.com/rancherfederal/[email protected]/pkg/collection/k3s/k3s.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.1.0-rc.10Review242026-06-16
v1.1.0-rc.1Review242026-06-16
v1.1.1-rc.1Review122026-06-16
v1.4.2-rc.1Review242026-06-16
v1.1.0-rc.9Review242026-06-16
v1.0.2-rc.4Review242026-06-16
v0.3.0-rc.2Review122026-06-16
v1.2.5Review242026-06-16
v0.3.0-rc.1Review122026-06-16
v1.1.1Review122026-06-16
v0.4.3Review242026-06-16
v1.2.3Review242026-06-16
v0.3.0Review122026-06-16
v1.0.0Review242026-06-16
v1.0.2Review242026-06-16
v1.2.3-dev.1Review242026-06-16
v0.2.0Review122026-06-16
v1.1.0-rc.2Review242026-06-16
v1.0.2-rc.3Review242026-06-16
v0.2.0-rc.3Review122026-06-16
v1.2.0-dev.1Review122026-06-16
v0.2.1Review122026-06-16
v1.0.0-rc.1Review242026-06-16
v0.4.2-rc.1Review242026-06-16
v0.4.0Review242026-06-16
v1.4.2Review242026-06-16
v1.4.3Review242026-06-16

Block this in CI

PkgRadar gates github.com/rancherfederal/k3ama (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/rancherfederal/[email protected]