PkgRadar

Go modules · proxy.golang.org

github.com/smartcontractkit/cre-cli

Remote Payload: matched "cURL "

Why PkgRadar flagged v1.17.0

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/smartcontractkit/[email protected]/cmd/client/eth_client.go
mediumRemote Payloadmatched "cURL " · github.com/smartcontractkit/[email protected]/cmd/creinit/creinit.go
mediumRemote Payloadmatched "cURL\n\t\t" · github.com/smartcontractkit/[email protected]/cmd/creinit/wizard.go
mediumRemote Payloadmatched "github.com/%s/releases/download" · github.com/smartcontractkit/[email protected]/cmd/update/update.go
mediumRemote Payloadmatched "wget " · github.com/smartcontractkit/[email protected]/cmd/workflow/workflow.go
mediumRemote Payloadmatched "cUrl " · github.com/smartcontractkit/[email protected]/internal/constants/constants.go
mediumRemote Payloadmatched "cUrl\n\t\t" · github.com/smartcontractkit/[email protected]/internal/settings/settings_generate.go
mediumRemote Payloadmatched "CURL " · github.com/smartcontractkit/[email protected]/internal/settings/settings_get.go
mediumRemote Payloadmatched "cURL " · github.com/smartcontractkit/[email protected]/internal/settings/workflow_settings.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.17.0Review1002026-05-30

Block this in CI

PkgRadar gates github.com/smartcontractkit/cre-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/smartcontractkit/[email protected]