PkgRadar

Go modules · proxy.golang.org

github.com/tencentblueking/bk-bscp

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.0.0-20260616033748-5f1eb76d9d13

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/tencentblueking/[email protected]/embed.go
mediumRemote Payloadmatched "curl " · github.com/tencentblueking/[email protected]/go.mod
mediumRemote Payloadmatched "curl " · github.com/tencentblueking/[email protected]/go.sum
mediumRemote Payloadmatched "curl " · github.com/tencentblueking/[email protected]/internal/runtime/ctl/cmd/helper.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260616033748-5f1eb76d9d13High risk482026-06-17
v0.0.0-20260616031735-9483a9925ed8High risk482026-06-17
v0.0.0-20260615123840-a6d79b9ed0e5High risk482026-06-16
v0.0.0-20260615091757-b180686413d1High risk482026-06-16
v0.0.0-20260615064417-42bdc20d8a61High risk482026-06-16
v0.0.0-20260615063513-c28d4ca691b8High risk482026-06-16
v0.0.0-20260610103443-bb8f52ce205aHigh risk482026-06-11
v0.0.0-20260609023815-679e49c89605High risk482026-06-10
v0.0.0-20260608091438-9675204cb394High risk482026-06-09
v0.0.0-20260608063900-4d15b3f081acHigh risk482026-06-09
v0.0.0-20260608022140-165ddadc78a6High risk482026-06-09
v0.0.0-20260601114635-d0a0801a9309High risk482026-06-02
v0.0.0-20260528121910-7b1a10d8c73fReview482026-05-29

Block this in CI

PkgRadar gates github.com/tencentblueking/bk-bscp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/tencentblueking/[email protected]