PkgRadar

Go modules · proxy.golang.org

github.com/scaleway/scaleway-cli/v2

Remote Payload: matched "curl "

Why PkgRadar flagged v2.56.2

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/scaleway/scaleway-cli/[email protected]/internal/namespaces/instance/v1/instance_cli.go
mediumRemote Payloadmatched "wget " · github.com/scaleway/scaleway-cli/[email protected]/internal/namespaces/k8s/v1/custom_pool.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/scaleway/scaleway-cli/[email protected]/internal/namespaces/mcp/server/server.go
mediumCredential file accessmatched "id_rsa" · github.com/scaleway/scaleway-cli/[email protected]/internal/namespaces/iam/v1alpha1/custom.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v2.56.2High risk612026-06-09

Block this in CI

PkgRadar gates github.com/scaleway/scaleway-cli/v2 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/scaleway/scaleway-cli/[email protected]