PkgRadar

Go modules · proxy.golang.org

github.com/stacklok/minder

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v0.0.0-20260613033617-437ace3a088a

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/stacklok/[email protected]/internal/auth/keycloak/client/client.go
mediumRemote Payloadmatched "cUrl " · github.com/stacklok/[email protected]/cmd/server/app/serve.go
mediumRemote Payloadmatched "cUrl " · github.com/stacklok/[email protected]/internal/auth/keycloak/keycloak.go
mediumRemote Payloadmatched "curl " · github.com/stacklok/[email protected]/internal/engine/actions/alert/security_advisory/security_advisory.go
mediumRemote Payloadmatched "curl " · github.com/stacklok/[email protected]/internal/engine/actions/remediate/gh_branch_protect/gh_branch_protect.go
mediumRemote Payloadmatched "curl " · github.com/stacklok/[email protected]/internal/engine/actions/remediate/pull_request/pull_request.go
mediumRemote Payloadmatched "curl " · github.com/stacklok/[email protected]/internal/engine/actions/remediate/rest/rest.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260613033617-437ace3a088aHigh risk952026-06-14
v0.0.0-20260612074617-0dcc010d1e31High risk952026-06-13
v0.1.3-0.20260611220816-fd280fdc2a3cHigh risk952026-06-13
v0.1.3-0.20260610235905-9c5063c739e9High risk952026-06-12
v0.1.3-0.20260604220734-196d981350b4High risk952026-06-06
v0.1.3-0.20260604061857-f0d4cba326e2High risk952026-06-05
v0.1.3-0.20260528133401-71a061f9ab60Review952026-05-29

Block this in CI

PkgRadar gates github.com/stacklok/minder (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/stacklok/[email protected]