PkgRadar

Go modules · proxy.golang.org

github.com/rubygems/rubygems.org

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260528021605-3e2efd28a832

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/rubygems/[email protected]/script/build_docker.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260616041746-ff66235f17c7Low risk02026-06-17
v0.0.0-20260615214703-70137517a564Low risk02026-06-17
v0.0.0-20260615142817-237ceea6a9c5Low risk02026-06-16
v0.0.0-20260609081811-5f6c5c3af8aaLow risk02026-06-10
v0.0.0-20260608225603-00784489a814Low risk02026-06-10
v0.0.0-20260604052147-298f33f4b087Low risk02026-06-05
v0.0.0-20260602162141-b1be0b571f7bLow risk02026-06-03
v0.0.0-20260601052309-f0c3ca0facedLow risk02026-06-02
v0.0.0-20260529140645-d4bc74cffe88Low risk02026-05-30
v0.0.0-20260528234750-ec3e496933a7Low risk02026-05-30
v0.0.0-20260528021605-3e2efd28a832Review202026-05-29

Block this in CI

PkgRadar gates github.com/rubygems/rubygems.org (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/rubygems/[email protected]