PkgRadar

Go modules · proxy.golang.org

github.com/ubuntu-core/snappy

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.0.0-20260615080135-f0c7df204a1d

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/ubuntu-core/[email protected]/client/interfaces.go
mediumRemote Payloadmatched "cURL " · github.com/ubuntu-core/[email protected]/cmd/snap/cmd_interface.go
mediumRemote Payloadmatched "cURL " · github.com/ubuntu-core/[email protected]/daemon/api_json.go
mediumRemote Payloadmatched "cURL " · github.com/ubuntu-core/[email protected]/interfaces/builtin/common.go
mediumRemote Payloadmatched "cURL " · github.com/ubuntu-core/[email protected]/interfaces/core.go
mediumRemote Payloadmatched "cURL " · github.com/ubuntu-core/[email protected]/interfaces/repo.go
mediumRemote Payloadmatched "cURL " · github.com/ubuntu-core/[email protected]/overlord/devicestate/devicestatetest/gadget.go
mediumRemote Payloadmatched "cURL " · github.com/ubuntu-core/[email protected]/overlord/devicestate/handlers_serial.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260615080135-f0c7df204a1dHigh risk1062026-06-16
v0.0.0-20260612130430-57190d4805f3High risk1062026-06-13
v0.0.0-20160308192407-a529af5f042fReview52026-06-13
v0.0.0-20260612102237-1190a97dc089High risk1062026-06-13
v0.0.0-20260611182021-2eab30f9aeceHigh risk1062026-06-13
v0.0.0-20260609115017-db3135315884High risk1062026-06-10
v0.0.0-20260605110015-190ec8d02e5cHigh risk1062026-06-06
v0.0.0-20260604061645-87e21bf7b0abHigh risk1062026-06-05
v0.0.0-20260529172857-76051e1a5f69Review1062026-05-30
v0.0.0-20260528115810-fbe858fecf72High risk1062026-05-30
v0.0.0-20260528110621-c5f77bf660d6High risk1062026-05-30

Block this in CI

PkgRadar gates github.com/ubuntu-core/snappy (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/ubuntu-core/[email protected]