PkgRadar

Go modules · proxy.golang.org

github.com/usewhale/deepseek-code-whale

Remote Payload: matched "curl "

Why PkgRadar flagged v0.1.43

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/usewhale/[email protected]/internal/policy/policy_defaults.go
mediumRemote Payloadmatched "iwr " · github.com/usewhale/[email protected]/internal/updatecheck/updatecheck.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/usewhale/[email protected]/internal/webfetch/webfetch.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.1.43High risk362026-06-12
v0.1.38High risk362026-06-12
v0.1.42High risk362026-06-12
v0.1.39High risk362026-06-12
v0.1.41-0.20260605040927-6b4689010e6dHigh risk362026-06-06
v0.1.40High risk362026-06-06
v0.1.37High risk362026-06-04
v0.1.32High risk362026-06-02
v0.1.27Review242026-06-02
v0.1.24Review242026-06-02
v0.1.33High risk362026-06-02
v0.1.32-0.20260601045739-9e0a2e6233caHigh risk362026-06-02
v0.1.26Review242026-06-02
v0.1.31High risk362026-06-02
v0.1.23-0.20260528014959-5a6054e5e888Review242026-05-30
v0.1.22Review242026-05-30
v0.1.24-0.20260528123226-0988090045c7Review242026-05-29
v0.1.23Review242026-05-29

Block this in CI

PkgRadar gates github.com/usewhale/deepseek-code-whale (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/usewhale/[email protected]