PkgRadar

Go modules · proxy.golang.org

github.com/telekom/sparrow

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260528100744-5d97c6fe3e6f

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/telekom/[email protected]/e2e/traceroute/shared/get_api.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.5.2-0.20260611162223-5d554287da09Low risk02026-06-12
v0.0.0-20260609092300-cb15ee363a32Low risk02026-06-10
v0.5.2-0.20260604080514-33f6d8227a37Low risk02026-06-05
v0.0.0-20260604080514-33f6d8227a37Low risk02026-06-05
v0.0.0-20260604080427-47de4d6686d1Low risk02026-06-05
v0.0.0-20260603233329-012a1c236c2fLow risk02026-06-04
v0.0.0-20260603233321-f4e9d559278cLow risk02026-06-04
v0.5.2-0.20260602063900-d10e269a8b27Low risk02026-06-03
v0.0.0-20260602063900-d10e269a8b27Low risk02026-06-03
v0.5.2-0.20260529102424-150ac9857d9cLow risk02026-06-03
v0.0.0-20260602042745-a93189fe7a92Low risk02026-06-03
v0.0.0-20260529102424-150ac9857d9cLow risk02026-05-30
v0.5.2-0.20260528220943-3a213551135bLow risk02026-05-30
v0.0.0-20260529101137-13d9af6f739dLow risk02026-05-30
v0.0.0-20260528220943-3a213551135bLow risk02026-05-29
v0.5.2-0.20260528220629-7e0e2c5a79b5Low risk02026-05-29
v0.0.0-20260528220629-7e0e2c5a79b5Low risk02026-05-29
v0.5.2-0.20260528122519-0d8d1a6faf5bLow risk02026-05-29
v0.0.0-20260528122831-cc148e0ba306Low risk02026-05-29
v0.0.0-20260528122817-eae44effb908Low risk02026-05-29
v0.0.0-20260528122750-163258b6ab77Low risk02026-05-29
v0.0.0-20260528122519-0d8d1a6faf5bLow risk02026-05-29
v0.0.0-20260528100744-5d97c6fe3e6fReview122026-05-29
v0.0.0-20260528100740-9352dea6b532Review122026-05-29
v0.0.0-20260528100730-5dd05469f452Review122026-05-29
v0.0.0-20260528100736-d724038e1bb4Review122026-05-29
v0.0.0-20260528100726-8eb9fd6fca4fReview122026-05-29

Block this in CI

PkgRadar gates github.com/telekom/sparrow (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/telekom/[email protected]