PkgRadar

Go modules · proxy.golang.org

github.com/superform-xyz/v2-core

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260527132108-79fb76af1f9b

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/superform-xyz/[email protected]/script/run/add_to_super_ledger_vnet.sh
mediumRemote Payloadmatched "curl " · github.com/superform-xyz/[email protected]/script/run/deploy_v2_staging_prod.sh
mediumRemote Payloadmatched "curl " · github.com/superform-xyz/[email protected]/script/run/extract_configurable_oracles.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260611071329-0be65107d59cLow risk02026-06-12
v0.0.0-20260604075022-fec78b52ef07Low risk02026-06-06
v0.0.0-20260602085408-5eecd2831eeeLow risk02026-06-03
v0.0.0-20260601101647-22ba27196113Low risk02026-06-02
v0.0.0-20260601054419-895ee759917aLow risk02026-06-02
v0.0.0-20260528153837-07b90e3ebf87Low risk02026-05-29
v0.0.0-20260528130321-1a6325f09b5bLow risk02026-05-29
v0.0.0-20260527132108-79fb76af1f9bReview362026-05-29

Block this in CI

PkgRadar gates github.com/superform-xyz/v2-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/superform-xyz/[email protected]