PkgRadar

Go modules · proxy.golang.org

k8s.io/perf-tests/clusterloader2

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.0-20260611185654-374a4dcf4efc

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · k8s.io/perf-tests/[email protected]/pkg/measurement/common/api_availability_measurement.go
mediumRemote Payloadmatched "curl " · k8s.io/perf-tests/[email protected]/pkg/measurement/common/etcd_metrics.go
mediumRemote Payloadmatched "curl " · k8s.io/perf-tests/[email protected]/pkg/measurement/common/profile.go
mediumRemote Payloadmatched "curl " · k8s.io/perf-tests/[email protected]/pkg/measurement/common/restart_apiserver.go
mediumRemote Payloadmatched "curl " · k8s.io/perf-tests/[email protected]/pkg/measurement/common/scheduler_latency.go
mediumRemote Payloadmatched "curl " · k8s.io/perf-tests/[email protected]/pkg/measurement/common/service_creation_latency.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260611185654-374a4dcf4efcHigh risk642026-06-12
v0.0.0-20260611182259-56c278798385High risk642026-06-12
v0.0.0-20260611103450-c00d27c22c17High risk642026-06-12
v0.0.0-20260610194656-c0b947af9df3High risk642026-06-12
v0.0.0-20260609141751-2f1bca953fc0High risk642026-06-11
v0.0.0-20260609121149-d4486ecab16bHigh risk642026-06-10
v0.0.0-20260608204745-4c65f154710fHigh risk642026-06-09
v0.0.0-20260608164548-9f98015e952dHigh risk642026-06-09
v0.0.0-20260608154403-515707b7e3ddHigh risk642026-06-09
v0.0.0-20260608085649-4fee76ce8d38High risk642026-06-09
v0.0.0-20260604220758-b29ed84ea02cHigh risk642026-06-06
v0.0.0-20260528084052-7c00b2b0ee98High risk642026-05-30
v0.0.0-20260528125850-7c74f74a31e5Review642026-05-29

Block this in CI

PkgRadar gates k8s.io/perf-tests/clusterloader2 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go k8s.io/perf-tests/[email protected]