PkgRadar

Go modules · proxy.golang.org

gitlab.com/data-custodian/custodian/components/contract-manager

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.0.0-20260610072030-447daae0132f

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · gitlab.com/data-custodian/custodian/components/[email protected]/internal/design/goa/definition/urls.go
mediumRemote Payloadmatched "cURL " · gitlab.com/data-custodian/custodian/components/[email protected]/pkg/ontology/ontology.go
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · gitlab.com/data-custodian/custodian/components/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260610072030-447daae0132fReview342026-06-11
v0.0.0-20260609115949-50d3802d2011Review342026-06-10
v0.0.0-20260609050105-6f3243289187Review342026-06-10
v0.0.0-20260605152505-adedfb96b527Review342026-06-06
v0.0.0-20260605105946-c301cd624c95Review342026-06-06
v0.0.0-20260605095037-996a9addfc04Review342026-06-06
v0.0.0-20260604163324-c28eba26253bReview342026-06-05
v0.0.0-20260604070036-0ee13fa9a9e7Review342026-06-05
v0.0.0-20260603111040-b5bfd4f35d9eReview342026-06-04
v0.0.0-20260602175018-ce58f6b8f46bReview342026-06-03
v0.0.0-20260602144318-47ad5ad5f773Review342026-06-03
v0.0.0-20260602122323-24965302e21bReview342026-06-03
v0.0.0-20260602121539-d6d5a0d7c3b1Review342026-06-03
v0.0.0-20260601074617-9b9270a22eeeReview342026-06-02

Block this in CI

PkgRadar gates gitlab.com/data-custodian/custodian/components/contract-manager (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go gitlab.com/data-custodian/custodian/components/[email protected]