PkgRadar

Go modules · proxy.golang.org

github.com/rgooch/dominator

Remote Payload: matched "cUrl "

Why PkgRadar flagged v0.0.0-20260614165530-635c2c497434

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · github.com/rgooch/[email protected]/imagebuilder/builder/api.go
mediumRemote Payloadmatched "cUrl " · github.com/rgooch/[email protected]/imagebuilder/builder/load.go
mediumRemote Payloadmatched "cURL " · github.com/rgooch/[email protected]/lib/gitutil/api.go
mediumRemote Payloadmatched "cURL " · github.com/rgooch/[email protected]/lib/gitutil/shallowClone.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260614165530-635c2c497434High risk682026-06-16
v0.0.0-20260614024035-5be830569cc6High risk682026-06-15
v0.0.0-20260611225313-13675a6d9d7dHigh risk682026-06-14
v0.0.0-20260601194134-11b15cdff48eHigh risk682026-06-05
v0.0.0-20260527022541-52381cf1794dReview682026-05-30

Block this in CI

PkgRadar gates github.com/rgooch/dominator (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/rgooch/[email protected]