PkgRadar

Go modules · proxy.golang.org

github.com/solo-io/gloo

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v1.22.0-beta6.0.20260604101934-4a36d8fb6133

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/solo-io/[email protected]/projects/envoyinit/hack/filter_types/filter_types.go
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/solo-io/[email protected]/projects/envoyinit/hack/filter_types_cli/filter_types.go
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/solo-io/[email protected]/projects/gloo/pkg/plugins/grpc/google_proto_apis.go
mediumRemote Payloadmatched "curl\n\n" · github.com/solo-io/[email protected]/pkg/utils/requestutils/curl/option.go
mediumRemote Payloadmatched "curl\n\n" · github.com/solo-io/[email protected]/pkg/utils/requestutils/curl/request.go
mediumRemote Payloadmatched "github.com/kubernetes-sigs/gateway-api/releases/download" · github.com/solo-io/[email protected]/projects/gloo/cli/pkg/cmd/check/kube_gateway.go
mediumRemote Payloadmatched "curl " · github.com/solo-io/[email protected]/projects/gloo/cli/pkg/cmd/gatewayapi/convert/command.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/solo-io/[email protected]/projects/gloo/cli/pkg/cmd/initpluginmanager/initpluginmanager.go
mediumRemote Payloadmatched "github.com/knative/serving/releases/download" · github.com/solo-io/[email protected]/projects/gloo/cli/pkg/cmd/install/knative.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.22.0-beta6.0.20260604101934-4a36d8fb6133High risk1322026-06-05
v0.0.0-20260604101934-4a36d8fb6133High risk1322026-06-05
v0.0.0-20260601164214-6728c633159fHigh risk1322026-06-05
v1.22.0-beta6.0.20260601164214-6728c633159fHigh risk1322026-06-05
v1.22.0-beta6.0.20260603182249-59b2e27141b9High risk1322026-06-05

Block this in CI

PkgRadar gates github.com/solo-io/gloo (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/solo-io/[email protected]