PkgRadar

Go modules · proxy.golang.org

go.foxforensics.dev/fox/v4

Remote Payload: matched "Curl "

Why PkgRadar flagged v4.58.5

SeveritySignalEvidence
mediumRemote Payloadmatched "Curl " · go.foxforensics.dev/fox/[email protected]/internal/cmd/str/str.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v4.58.5Review122026-06-12
v4.58.3Review122026-06-11
v4.58.4Review122026-06-11
v4.58.2Review122026-06-10
v4.53.0Low risk02026-06-09
v4.53.1Low risk02026-06-09
v4.54.1Review122026-06-09
v4.58.1Review122026-06-09
v4.57.1Review122026-06-04
v4.57.0Review122026-06-04

Block this in CI

PkgRadar gates go.foxforensics.dev/fox/v4 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go go.foxforensics.dev/fox/[email protected]