PkgRadar

Go modules · proxy.golang.org

gopkg.in/juju/charm.v5

Remote Payload: matched "curl "

Why PkgRadar flagged v5.0.0-20150820175011-aad3e4a7a176

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · gopkg.in/juju/[email protected]/charmrepo/charmstore.go
mediumRemote Payloadmatched "curl " · gopkg.in/juju/[email protected]/charmrepo/legacy.go
mediumRemote Payloadmatched "curl " · gopkg.in/juju/[email protected]/charmrepo/local.go
mediumRemote Payloadmatched "curl " · gopkg.in/juju/[email protected]/charmrepo/params.go
mediumRemote Payloadmatched "curl " · gopkg.in/juju/[email protected]/charmrepo/repo.go
mediumRemote Payloadmatched "curl " · gopkg.in/juju/[email protected]/testing/charm.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v5.0.0-20150820175011-aad3e4a7a176High risk502026-06-05

Block this in CI

PkgRadar gates gopkg.in/juju/charm.v5 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go gopkg.in/juju/[email protected]