PkgRadar

Go modules · proxy.golang.org

github.com/spore-host/spawn

Remote Payload: matched "curl "

Why PkgRadar flagged v0.54.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/spore-host/[email protected]/cmd/app.go
mediumRemote Payloadmatched "Invoke-WebRequest" · github.com/spore-host/[email protected]/cmd/launch.go
mediumRemote Payloadmatched "curl " · github.com/spore-host/[email protected]/lambda/pipeline-orchestrator/main.go
mediumRemote Payloadmatched "curl " · github.com/spore-host/[email protected]/pkg/launcher/bootstrap.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/spore-host/[email protected]/pkg/plugin/registry.go
mediumRemote Payloadmatched "curl " · github.com/spore-host/[email protected]/pkg/userdata/mpi.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.54.0High risk872026-06-18
v0.55.0High risk872026-06-18
v0.57.0High risk872026-06-17
v0.53.0High risk872026-06-17
v0.52.0High risk872026-06-15
v0.51.0High risk872026-06-15
v0.50.0High risk872026-06-15
v0.49.0High risk872026-06-15
v0.48.2-0.20260614003609-ef157d3272dfHigh risk872026-06-15
v0.48.1High risk872026-06-15
v0.48.0High risk872026-06-14
v0.47.0High risk872026-06-14
v0.46.0High risk872026-06-14
v0.45.1High risk872026-06-14
v0.45.1-0.20260613020045-86efb572a6a2High risk872026-06-14
v0.45.0High risk872026-06-14
v0.44.2High risk872026-06-13
v0.43.1-0.20260612175430-0809fb533d71High risk872026-06-13
v0.43.0High risk872026-06-13
v0.42.0High risk872026-06-13
v0.41.0High risk872026-06-13
v0.40.0High risk752026-06-12
v0.38.0High risk752026-06-12
v0.37.1High risk752026-06-12
v0.36.12High risk802026-06-12
v0.37.3High risk752026-06-12
v0.38.1High risk752026-06-12
v0.39.1-0.20260610173117-ede5fecfc37dHigh risk752026-06-12
v0.37.0High risk802026-06-12
v0.37.2High risk752026-06-12
v0.36.12-0.20260603205155-d22af24fb321High risk852026-06-04
v0.36.11High risk852026-06-04
v0.36.9High risk852026-06-04
v0.36.8High risk852026-06-04
v0.36.7High risk852026-06-04
v0.36.3High risk852026-06-01
v0.36.4High risk852026-06-01
v0.36.6High risk852026-06-01
v0.36.5High risk852026-06-01
v0.36.0Review852026-05-31
v0.36.2Review852026-05-31
v0.36.1Review852026-05-30

Block this in CI

PkgRadar gates github.com/spore-host/spawn (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/spore-host/[email protected]