PkgRadar

Go modules · proxy.golang.org

github.com/yangkenneth/cosign/v3

Remote Payload: matched "curl "

Why PkgRadar flagged v3.0.0-20260607222312-8f7f96ccc1a9

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/yangkenneth/cosign/[email protected]/cmd/cosign/cli/signcommon/common.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v3.0.0-20260607222312-8f7f96ccc1a9Review122026-06-08
v3.0.0-20251218164947-627da1a0ccd1Review122026-06-08
v3.0.0-20260607214713-3604a89f1efcReview122026-06-08

Block this in CI

PkgRadar gates github.com/yangkenneth/cosign/v3 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/yangkenneth/cosign/[email protected]