PkgRadar

Go modules · proxy.golang.org

k8s.io/KUBERNETES

Remote Payload: matched "curl "

Why PkgRadar flagged v1.37.0-alpha.1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · k8s.io/[email protected]/cmd/kubeadm/app/util/apiclient/wait.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.37.0-alpha.1Review122026-06-13
v0.0.0-20260606164427-643e407efef8Review122026-06-07
v0.0.0-20260604173553-f92c74d803deReview122026-06-06
v0.0.0-20260603163955-862d42080ff3Review122026-06-04
v0.0.0-20260603151959-7a1385a332e5Review122026-06-04
v0.0.0-20260603130948-e0c1c5bd3d18Review122026-06-04
v0.0.0-20260603115946-a94f8bfc3eb5Review122026-06-04
v0.0.0-20260602110954-e4606044ad20Review122026-06-03
v0.0.0-20260602063652-9f192ba95aa5Review122026-06-03

Block this in CI

PkgRadar gates k8s.io/KUBERNETES (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go k8s.io/[email protected]