PkgRadar

Go modules · proxy.golang.org

github.com/vinicioslugli/deepseek-code-whale

Remote Payload: matched "curl "

Why PkgRadar flagged v0.1.34-0.20260601232739-c38158c7a27a

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/vinicioslugli/[email protected]/internal/policy/policy_defaults.go
mediumRemote Payloadmatched "iwr " · github.com/vinicioslugli/[email protected]/internal/updatecheck/updatecheck.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/vinicioslugli/[email protected]/internal/webfetch/webfetch.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.1.34-0.20260601232739-c38158c7a27aHigh risk362026-06-02
v0.1.14Low risk02026-06-02
v0.1.18Review242026-06-02
v0.1.0Low risk02026-06-02
v0.1.3Low risk02026-06-02
v0.1.31High risk362026-06-02
v0.1.10Low risk02026-06-02
v0.1.26Review242026-06-02
v0.1.28High risk362026-06-02
v0.1.30High risk362026-06-02
v0.1.24Review242026-06-02
v0.1.12Low risk02026-06-02
v0.1.6Low risk02026-06-02
v0.1.23Review242026-06-02

Block this in CI

PkgRadar gates github.com/vinicioslugli/deepseek-code-whale (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/vinicioslugli/[email protected]