PkgRadar

Go modules · proxy.golang.org

petris.dev/toby

Remote Payload: matched "curl "

Why PkgRadar flagged v0.3.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · petris.dev/[email protected]/internal/tools/emdash/emdash.go
mediumRemote Payloadmatched "curl " · petris.dev/[email protected]/internal/tools/forgejocli/forgejocli.go
mediumRemote Payloadmatched "curl " · petris.dev/[email protected]/internal/tools/githubcli/githubcli.go
mediumRemote Payloadmatched "curl " · petris.dev/[email protected]/internal/tools/gitlabcli/gitlabcli.go
mediumRemote Payloadmatched "curl " · petris.dev/[email protected]/internal/tools/grok/grok.go
mediumRemote Payloadmatched "curl " · petris.dev/[email protected]/internal/tools/uv/uv.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.11.1Low risk02026-06-10
v0.12.0Low risk02026-06-10
v0.11.0Low risk02026-06-10
v0.7.1Review122026-06-10
v0.15.1Low risk02026-06-08
v0.15.0Low risk02026-06-08
v0.14.2Low risk02026-06-08
v0.14.1Low risk02026-06-07
v0.14.0Low risk02026-06-07
v0.13.0Low risk02026-06-07
v0.12.1Low risk02026-06-07
v0.9.0Low risk02026-06-06
v0.8.0Review122026-06-04
v0.3.0High risk502026-06-03
v0.6.0Review122026-06-03
v0.4.1High risk502026-06-01
v0.3.2Review502026-05-31
v0.3.1Review502026-05-30
v0.2.0Review362026-05-30
v0.1.0Review362026-05-30

Block this in CI

PkgRadar gates petris.dev/toby (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go petris.dev/[email protected]