PkgRadar

Go modules · proxy.golang.org

github.com/snapcore/snappy

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.0.0-20260615182726-bb3d7af09c0d

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/snapcore/[email protected]/client/interfaces.go
mediumRemote Payloadmatched "cURL " · github.com/snapcore/[email protected]/cmd/snap/cmd_interface.go
mediumRemote Payloadmatched "cURL " · github.com/snapcore/[email protected]/daemon/api_json.go
mediumRemote Payloadmatched "cURL " · github.com/snapcore/[email protected]/interfaces/builtin/common.go
mediumRemote Payloadmatched "cURL " · github.com/snapcore/[email protected]/interfaces/core.go
mediumRemote Payloadmatched "cURL " · github.com/snapcore/[email protected]/interfaces/repo.go
mediumRemote Payloadmatched "cURL " · github.com/snapcore/[email protected]/overlord/devicestate/devicestatetest/gadget.go
mediumRemote Payloadmatched "cURL " · github.com/snapcore/[email protected]/overlord/devicestate/handlers_serial.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260615182726-bb3d7af09c0dHigh risk1062026-06-16
v0.0.0-20260612130430-57190d4805f3High risk1062026-06-14
v0.0.0-20260608071743-e8dc9de8fd5fHigh risk1062026-06-09
v0.0.0-20260606162417-34baaae4213dHigh risk1062026-06-08
v0.0.0-20260605110015-190ec8d02e5cHigh risk1062026-06-06
v0.0.0-20260602213031-374ec1a74d1eHigh risk1062026-06-04
v0.0.0-20260529172857-76051e1a5f69High risk1062026-06-01
v0.0.0-20260528182158-3f60bb7aa77bReview1062026-05-30

Block this in CI

PkgRadar gates github.com/snapcore/snappy (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/snapcore/[email protected]