PkgRadar

Go modules · proxy.golang.org

kcl-lang.io/cli

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged v0.12.5-0.20260615120034-c8996dfd2607

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · kcl-lang.io/[email protected]/cmd/kcl/commands/import.go
mediumRemote Payloadmatched "curl " · kcl-lang.io/[email protected]/cmd/kcl/commands/server.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.12.5-0.20260615120034-c8996dfd2607Review242026-06-16

Block this in CI

PkgRadar gates kcl-lang.io/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go kcl-lang.io/[email protected]