PkgRadar

Go modules · proxy.golang.org

kraftkit.sh

Remote Payload: matched "curl "

Why PkgRadar flagged v0.12.13-2-gb95869ad

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · [email protected]/internal/update/update.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.12.13-2-gb95869adReview122026-06-09
v0.12.12-7-g8f5e5dd3Review122026-05-30
v0.12.12-5-g79065b3aReview122026-05-30
v0.0.0-20260529102957-8f5e5dd34ac0Review122026-05-30
v0.12.13Review122026-05-30
v0.0.0-20260529094744-79065b3adc94Review122026-05-30
v0.12.12Review242026-05-29

Block this in CI

PkgRadar gates kraftkit.sh (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go [email protected]
kraftkit.sh — Go modules security scan | PkgRadar