PkgRadar

Go modules · proxy.golang.org

github.com/smark91/limbo

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.4.0

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/smark91/[email protected]/internal/api/requests.go
mediumRemote Payloadmatched "cURL " · github.com/smark91/[email protected]/internal/config/config.go
mediumRemote Payloadmatched "cURL\n\t" · github.com/smark91/[email protected]/internal/scanner/notifier.go
mediumRemote Payloadmatched "cURL " · github.com/smark91/[email protected]/internal/seerr/client.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.4.0High risk482026-06-07
v0.1.1High risk362026-06-07
v0.8.0High risk482026-06-07
v0.3.0-tailwindHigh risk362026-06-07
v0.1.5High risk362026-06-07
v0.10.0High risk482026-06-07
v0.11.0High risk482026-06-07
v0.12.0High risk482026-06-07
v0.2.0High risk362026-06-07
v0.3.0High risk362026-06-07
v0.5.0High risk482026-06-07
v0.6.0High risk482026-06-07
v0.7.0High risk482026-06-07
v0.1.0High risk362026-06-07
v0.1.2High risk362026-06-07
v0.1.3High risk362026-06-07
v0.1.4High risk362026-06-07
v0.9.0High risk482026-06-07
v0.12.1High risk482026-06-07

Block this in CI

PkgRadar gates github.com/smark91/limbo (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/smark91/[email protected]