PkgRadar

Go modules · proxy.golang.org

github.com/sv-oss/restish/v2

Remote Payload: matched "cURL "

Why PkgRadar flagged v2.1.2

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/sv-oss/restish/[email protected]/internal/cli/api.go
mediumRemote Payloadmatched "curl " · github.com/sv-oss/restish/[email protected]/internal/cli/api_auth.go
mediumRemote Payloadmatched "cURL " · github.com/sv-oss/restish/[email protected]/internal/cli/cli.go
mediumRemote Payloadmatched "cURL " · github.com/sv-oss/restish/[email protected]/internal/cli/config_cmd.go
mediumRemote Payloadmatched "cURL " · github.com/sv-oss/restish/[email protected]/internal/cli/doctor.go
mediumRemote Payloadmatched "cURL\n\t\t" · github.com/sv-oss/restish/[email protected]/internal/cli/generated.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/sv-oss/restish/[email protected]/internal/cli/theme.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v2.1.2High risk842026-06-18
v2.2.1-0.20260616032919-f34ae93eb5beHigh risk842026-06-18
v2.0.0High risk842026-06-18
v2.1.0High risk842026-06-18
v2.2.1-0.20260617102503-55e45a829a20High risk842026-06-18
v2.0.0-20260616032919-f34ae93eb5beHigh risk842026-06-18

Block this in CI

PkgRadar gates github.com/sv-oss/restish/v2 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/sv-oss/restish/[email protected]