PkgRadar

Go modules · proxy.golang.org

go.kenn.io/msgvault

Remote Payload: matched "curl "

Why PkgRadar flagged v0.15.2-0.20260604031318-a34c50d2e5ea

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · go.kenn.io/[email protected]/cmd/msgvault/cmd/export_token.go
mediumRemote Payloadmatched "github.com/kenn-io/msgvault/releases/download" · go.kenn.io/[email protected]/internal/update/update.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.15.2-0.20260604031318-a34c50d2e5eaReview242026-06-08
v0.15.1Review242026-06-08
v0.1.2Low risk02026-06-08
v0.1.3Low risk02026-06-08
v0.1.5Low risk02026-06-08
v0.10.0Review122026-06-08
v0.11.0Review122026-06-08
v0.12.1Review122026-06-08
v0.13.0Review122026-06-08
v0.1.0Low risk02026-06-08
v0.1.1Low risk02026-06-08
v0.14.0Review122026-06-08
v0.14.1Review122026-06-08
v0.15.0Review242026-06-08
v0.2.0Low risk02026-06-08
v0.4.0Low risk02026-06-08
v0.6.2Low risk02026-06-08
v0.6.3Low risk02026-06-08
v0.6.4Low risk02026-06-08
v0.7.0Low risk02026-06-08
v0.5.0Low risk02026-06-08
v0.5.1Low risk02026-06-08
v0.5.2Low risk02026-06-08
v0.13.1Review122026-06-08
v0.6.0Low risk02026-06-08
v0.6.1Low risk02026-06-08
v0.6.5Low risk02026-06-08
v0.12.0Review122026-06-08
v0.1.4Low risk02026-06-08
v0.9.0Review122026-06-08
v0.3.0Low risk02026-06-08
v0.8.0Review122026-06-08

Block this in CI

PkgRadar gates go.kenn.io/msgvault (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go go.kenn.io/[email protected]