Go modules · proxy.golang.org
github.com/tevfik/gleann
Remote Payload: matched "curl "
Why PkgRadar flagged v1.5.1-0.20260601113219-6d5c530f6e9f
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "curl " · github.com/tevfik/[email protected]/cmd/gleann/cmd_install.go |
| medium | Remote Payload | matched "curl " · github.com/tevfik/[email protected]/cmd/gleann/cmd_memory.go |
| medium | Remote Payload | matched "curl " · github.com/tevfik/[email protected]/internal/tui/install.go |
| medium | Go Mod Replace Local | go.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/tevfik/[email protected]/go.mod |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v1.5.1-0.20260601113219-6d5c530f6e9f | High risk | 46 | 2026-06-03 |
v0.0.0-20260601113219-6d5c530f6e9f | High risk | 46 | 2026-06-03 |
v1.5.0 | High risk | 46 | 2026-06-02 |
v0.0.0-20260531181835-d1130a7431f0 | High risk | 46 | 2026-06-02 |
Block this in CI
pkgradar gate --ecosystem go github.com/tevfik/[email protected]