PkgRadar

Go modules · proxy.golang.org

github.com/solo-io/gloo_2

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v1.22.0-beta7

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/solo-io/[email protected]/projects/envoyinit/hack/filter_types/filter_types.go
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/solo-io/[email protected]/projects/envoyinit/hack/filter_types_cli/filter_types.go
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/solo-io/[email protected]/projects/gloo/pkg/plugins/grpc/google_proto_apis.go
mediumRemote Payloadmatched "curl\n\n" · github.com/solo-io/[email protected]/pkg/utils/requestutils/curl/option.go
mediumRemote Payloadmatched "curl\n\n" · github.com/solo-io/[email protected]/pkg/utils/requestutils/curl/request.go
mediumRemote Payloadmatched "github.com/kubernetes-sigs/gateway-api/releases/download" · github.com/solo-io/[email protected]/projects/gloo/cli/pkg/cmd/check/kube_gateway.go
mediumRemote Payloadmatched "curl " · github.com/solo-io/[email protected]/projects/gloo/cli/pkg/cmd/gatewayapi/convert/command.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/solo-io/[email protected]/projects/gloo/cli/pkg/cmd/initpluginmanager/initpluginmanager.go
mediumRemote Payloadmatched "github.com/knative/serving/releases/download" · github.com/solo-io/[email protected]/projects/gloo/cli/pkg/cmd/install/knative.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.22.0-beta7High risk1322026-06-06
v1.20.18High risk1172026-06-06
v1.21.8High risk1322026-06-06
v1.19.16High risk1172026-06-02
v1.22.0-beta5High risk1322026-06-02
v1.21.5High risk1322026-06-02
v1.19.17High risk1172026-06-02
v1.20.16High risk1172026-06-02
v1.20.15High risk1172026-06-02
v1.18.38High risk1052026-06-02
v1.22.0-beta6High risk1322026-06-02
v1.21.6High risk1322026-06-02

Block this in CI

PkgRadar gates github.com/solo-io/gloo_2 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/solo-io/[email protected]