PkgRadar

Go modules · proxy.golang.org

github.com/shareed2k/honey

Remote Payload: matched "curl "

Why PkgRadar flagged v0.3.6-0.20260613212827-50b53c48a24a

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/shareed2k/[email protected]/internal/cli/egress.go
mediumRemote Payloadmatched "cURL " · github.com/shareed2k/[email protected]/internal/pvelxc/qemu_vnc.go
mediumRemote Payloadmatched "github.com/shareed2k/honey/releases/download" · github.com/shareed2k/[email protected]/internal/transferagent/download_embed.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.3.6-0.20260613212827-50b53c48a24aHigh risk512026-06-16
v0.0.0-next.20260614.24High risk512026-06-16
v0.0.0-next.20260613.23High risk512026-06-14
v0.3.5High risk512026-06-14
v0.0.0-next.20260612.22High risk512026-06-14
v0.0.0-next.20260612.20High risk512026-06-13
v0.0.0-next.20260605.16High risk512026-06-11
v0.3.5-0.20260610075436-788e7468b78eHigh risk512026-06-11
v0.0.0-next.20260607.17High risk512026-06-11
v0.0.0-next.20260609.19High risk512026-06-11
v0.0.0-next.20260531.3High risk462026-06-04
v0.0.0-next.20260601.4High risk512026-06-04
v0.3.3High risk512026-06-04
v0.3.2-0.20260529140947-31f488598fc3Review342026-05-31
v0.3.0Review342026-05-31
v0.3.2Review342026-05-31
v0.3.1Review342026-05-31

Block this in CI

PkgRadar gates github.com/shareed2k/honey (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/shareed2k/[email protected]