PkgRadar

Go modules · proxy.golang.org

github.com/vasic-digital/herald

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260528001920-9de831794109

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/vasic-digital/[email protected]/tests/test_wave6.5_lifecycle.sh
mediumRemote Payloadmatched "curl " · github.com/vasic-digital/[email protected]/tests/test_wave6_live_loop.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.6.1-0.20260531113351-8b2ceb688f7dLow risk02026-06-01
v0.0.0-20260531113351-8b2ceb688f7dLow risk02026-06-01
v0.0.0-20260531111407-bff48a53a8baLow risk02026-06-01
v0.6.1-0.20260531091722-7b1ede76bc2cLow risk02026-06-01
v0.0.0-20260531091722-7b1ede76bc2cLow risk02026-06-01
v0.0.0-20260529062824-ebd88add4297Low risk02026-05-30
v0.0.0-20260529061447-ee6df5b80b85Low risk02026-05-30
v0.6.1-0.20260529061447-ee6df5b80b85Low risk02026-05-30
v0.0.0-20260529055552-b7b66c62019aLow risk02026-05-30
v0.0.0-20260529053222-904fb55188deLow risk02026-05-30
v0.6.1-0.20260528190520-8a3d240c84f8Low risk02026-05-30
v0.0.0-20260528190520-8a3d240c84f8Low risk02026-05-30
v0.6.0Low risk02026-05-30
v0.0.0-20260528001920-9de831794109Review292026-05-29

Block this in CI

PkgRadar gates github.com/vasic-digital/herald (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/vasic-digital/[email protected]