PkgRadar

Go modules · proxy.golang.org

github.com/xz-dev/rclone

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v1.70.0

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/xz-dev/[email protected]/vfs/vfs.go
mediumRemote Payloadmatched "cURL " · github.com/xz-dev/[email protected]/backend/azurefiles/azurefiles.go
mediumRemote Payloadmatched "cURL " · github.com/xz-dev/[email protected]/backend/ulozto/api/types.go
mediumRemote Payloadmatched "cURL " · github.com/xz-dev/[email protected]/backend/yandex/api/types.go
mediumRemote Payloadmatched "cURL " · github.com/xz-dev/[email protected]/backend/yandex/yandex.go
mediumRemote Payloadmatched "cURL\n\t" · github.com/xz-dev/[email protected]/lib/http/context.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.70.0High risk952026-06-08
v1.74.0High risk1192026-06-08
v1.74.1-0.20260504081948-f346ac3c95cfHigh risk1192026-06-08

Block this in CI

PkgRadar gates github.com/xz-dev/rclone (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/xz-dev/[email protected]