PkgRadar

Go modules · proxy.golang.org

github.com/sparkwing-dev/sparkwing

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.7.0

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/sparkwing-dev/[email protected]/cmd/sparkwing/spark.go
mediumRemote Payloadmatched "github.com/\" + updateRepo + \"/releases/download" · github.com/sparkwing-dev/[email protected]/cmd/sparkwing/update.go
mediumRemote Payloadmatched "cURL " · github.com/sparkwing-dev/[email protected]/internal/bincache/bincache.go
mediumRemote Payloadmatched "cURL " · github.com/sparkwing-dev/[email protected]/internal/orchestrator/run_node_remote.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.7.0High risk482026-06-01
v0.7.2-0.20260531061743-cba244c2d163High risk482026-06-01
v0.7.1High risk482026-06-01
v0.6.4-0.20260531012526-06a5f6e0c41dHigh risk482026-06-01
v0.6.3High risk482026-06-01
v0.6.2High risk482026-05-31
v0.6.1High risk482026-05-31
v0.6.0Review482026-05-31
v0.5.2-0.20260528145154-eeb0a923f743Review482026-05-29
v0.5.1Review482026-05-29

Block this in CI

PkgRadar gates github.com/sparkwing-dev/sparkwing (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/sparkwing-dev/[email protected]