PkgRadar

Go modules · proxy.golang.org

github.com/steveyegge/beads

Remote Payload: matched "curl "

Why PkgRadar flagged v1.0.6-0.20260615070122-8e18581dc0dd

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/steveyegge/[email protected]/cmd/bd/doctor/version.go
mediumRemote Payloadmatched "cURL " · github.com/steveyegge/[email protected]/cmd/bd/init.go
mediumRemote Payloadmatched "curl " · github.com/steveyegge/[email protected]/cmd/bd/init_templates.go
mediumRemote Payloadmatched "curl " · github.com/steveyegge/[email protected]/cmd/bd/store_factory_nocgo.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.0.6-0.20260615070122-8e18581dc0ddHigh risk482026-06-16
v1.0.6-0.20260614195710-605f7fcc355dHigh risk482026-06-15
v1.0.6-0.20260613224319-7f30ac3c1064High risk482026-06-15
v1.0.5-0.20260611054652-dc0561af28e9High risk482026-06-15
v1.0.6-0.20260612154203-1825cf3572ceHigh risk482026-06-13
v0.0.0-20260601214237-fbcee6c6246cHigh risk482026-06-13
v1.0.6-0.20260612021552-27bbecbd11b3High risk482026-06-13
v1.0.6-0.20260611154156-88d1c2b5efc6High risk482026-06-12
v1.0.6-0.20260610034119-f97fd4a8b5daHigh risk482026-06-11
v1.0.6-0.20260610025303-99c70904f6ffHigh risk482026-06-11
v1.0.6-0.20260608183114-9a1c88b63aeeHigh risk482026-06-10
v1.0.6-0.20260530054454-8de88e15b7d0High risk482026-06-10
v1.0.6-0.20260607220307-d4d58965d22fHigh risk482026-06-09
v1.0.6-0.20260601214237-fbcee6c6246cHigh risk482026-06-02
v1.0.6-0.20260601020050-7d7ff50c8e64High risk482026-06-02
v0.21.8-0.20251105075950-ff8f6ecadff8Review122026-06-01
v1.0.6-0.20260531005639-848d0d7b6c93High risk482026-06-01
v1.0.6-0.20260529212849-6d7eb5b3b1a9Review482026-05-30
v1.0.5Review482026-05-30
v1.0.5-0.20260528224138-278b24ab4bb0Review482026-05-30
v1.0.5-0.20260528153346-a011761e5ed4Review482026-05-29

Block this in CI

PkgRadar gates github.com/steveyegge/beads (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/steveyegge/[email protected]