PkgRadar

Go modules · proxy.golang.org

github.com/stackql/any-sdk

Remote Payload: matched "cUrl "

Why PkgRadar flagged v0.5.3-alpha06.0.20260528233302-ab78cab53e34

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · github.com/stackql/[email protected]/internal/anysdk/loader.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/stackql/[email protected]/internal/anysdk/registry.go
mediumRemote Payloadmatched "cURL " · github.com/stackql/[email protected]/public/discovery/discovery.go
mediumRemote Payloadmatched "cURL " · github.com/stackql/[email protected]/public/formulation/formulation.go
mediumRemote Payloadmatched "cURL " · github.com/stackql/[email protected]/public/formulation/wrappers.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.5.3-alpha06.0.20260528233302-ab78cab53e34High risk652026-06-04
v0.5.3-alpha02High risk652026-06-04
v0.5.3-alpha03High risk652026-06-04
v0.5.3-alpha07High risk652026-05-30
v0.5.3-alpha06High risk652026-05-30
v0.5.3-alpha05High risk652026-05-30

Block this in CI

PkgRadar gates github.com/stackql/any-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/stackql/[email protected]
github.com/stackql/any-sdk — Go modules security scan | PkgRadar