PkgRadar

Go modules · proxy.golang.org

scenery.sh

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.1.3-0.20260612080544-e24c0b54e85b

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · [email protected]/cmd/scenery/dev_frontends.go
mediumRemote Payloadmatched "cURL " · [email protected]/cmd/scenery/grafana.go
mediumRemote Payloadmatched "github.com/VictoriaMetrics/%s/releases/download" · [email protected]/cmd/scenery/victoria.go
mediumRemote Payloadmatched "cURL " · [email protected]/internal/clientgen/typescript_render.go
mediumRemote Payloadmatched "github.com/caddyserver/caddy/releases/download/v2.11.3/caddy_2.11.3_linux_amd64.tar.gz\\\",\\n \\\"sha256\\\": \\\"3894577b14657feab3624d782f64175050211e52a228a6f57b4f24f4b0d970f3\\\",\\n \\\"extract\\\": \\\"caddy\\\"\\n },\\n \\\"darwin/arm64\\\": {\\n \\\"archive\\\": \\\"tar.gz\\\",\\n \\\"url\\\": \\\"https://github.com/caddyserver/caddy/releases/download/v2.11.3/caddy_2.11.3_mac_arm64.tar.gz\\\",\\n \\\"sha256\\\": \\\"b37757be82ef630dddf359e6f1685731a1c657576ce80c469e0e3e6a8fb49e9d\\\",\\n \\\"extract\\\": \\\"caddy\\\"\\n }\\n }\\n },\\n {\\n \\\"name\\\": \\\"dnsmasq\\\",\\n \\\"kind\\\": \\\"binary\\\",\\n \\\"version\\\": \\\"2.92\\\",\\n \\\"license\\\": \\\"GPL-2.0-only OR GPL-3.0-only\\\",\\n \\\"default_binary\\\": \\\"dnsmasq\\\",\\n \\\"binaries\\\": [\\\"dnsmasq\\\"],\\n \\\"platforms\\\": {\\n \\\"linux/amd64\\\": {\\n \\\"archive\\\": \\\"tar.gz\\\",\\n \\\"url\\\": \\\"https://thekelleys.org.uk/dnsmasq/dnsmasq-2.92.tar.gz\\\",\\n \\\"sha256\\\": \\\"fd908e79ff37f73234afcb6d3363f78353e768703d92abd8e3220ade6819b1e1\\\",\\n \\\"extract\\\": \\\"dnsmasq\\\",\\n \\\"strip_components\\\": 1,\\n \\\"build\\\": [\\n \\\"make install PREFIX={install}\\\"\\n ],\\n \\\"build_output\\\": \\\"sbin/dnsmasq\\\"\\n },\\n \\\"darwin/arm64\\\": {\\n \\\"archive\\\": \\\"tar.gz\\\",\\n \\\"url\\\": \\\"https://thekelleys.org.uk/dnsmasq/dnsmasq-2.92.tar.gz\\\",\\n \\\"sha256\\\": \\\"fd908e79ff37f73234afcb6d3363f78353e768703d92abd8e3220ade6819b1e1\\\",\\n \\\"extract\\\": \\\"dnsmasq\\\",\\n \\\"strip_components\\\": 1,\\n \\\"build\\\": [\\n \\\"make install PREFIX={install} CFLAGS=\\\\\\\"-D__APPLE_USE_RFC_3542\\\\\\\"\\\"\\n ],\\n \\\"build_output\\\": \\\"sbin/dnsmasq\\\"\\n }\\n }\\n },\\n {\\n \\\"name\\\": \\\"victoriametrics-metrics-datasource\\\",\\n \\\"kind\\\": \\\"plugin\\\",\\n \\\"version\\\": \\\"0.24.0\\\",\\n \\\"license\\\": \\\"Apache-2.0\\\"\\n },\\n {\\n \\\"name\\\": \\\"victoriametrics-logs-datasource\\\",\\n \\\"kind\\\": \\\"plugin\\\",\\n \\\"version\\\": \\\"0.27.1\\\",\\n \\\"license\\\": \\\"Apache-2.0\\\"\\n },\\n {\\n \\\"name\\\": \\\"victoria-metrics\\\",\\n \\\"kind\\\": \\\"binary\\\",\\n \\\"version\\\": \\\"v1.141.0\\\",\\n \\\"license\\\": \\\"Apache-2.0\\\",\\n \\\"default_binary\\\": \\\"victoria-metrics-prod\\\",\\n \\\"binaries\\\": [\\\"victoria-metrics-prod\\\", \\\"victoria-metrics\\\"],\\n \\\"platforms\\\": {\\n \\\"linux/amd64\\\": {\\n \\\"archive\\\": \\\"tar.gz\\\",\\n \\\"url\\\": \\\"https://github.com/VictoriaMetrics/VictoriaMetrics/releases/download/v1.141.0/victoria-metrics-linux-amd64-v1.141.0.tar.gz\\\",\\n \\\"sha256\\\": \\\"774cba5b382d7ee132a9152aee3916cf34dd52fae1d6d17146d0b9157bc6de14\\\",\\n \\\"extract\\\": \\\"victoria-metrics-prod\\\"\\n },\\n \\\"darwin/arm64\\\": {\\n \\\"archive\\\": \\\"tar.gz\\\",\\n \\\"url\\\": \\\"https://github.com/VictoriaMetrics/VictoriaMetrics/releases/download/v1.141.0/victoria-metrics-darwin-arm64-v1.141.0.tar.gz\\\",\\n \\\"sha256\\\": \\\"7d07254740bb5201ea8d85f110f6a80f827b8b28615ca1c6a4adf1cfae85719a\\\",\\n \\\"extract\\\": \\\"victoria-metrics-prod\\\"\\n }\\n },\\n \\\"images\\\": [\\n {\\n \\\"ref\\\": \\\"victoriametrics/victoria-metrics:v1.141.0\\\",\\n \\\"optional\\\": true,\\n \\\"usage\\\": \\\"dev.observability.metrics\\\",\\n \\\"stability\\\": \\\"unstable\\\"\\n }\\n ]\\n },\\n {\\n \\\"name\\\": \\\"victoria-logs\\\",\\n \\\"kind\\\": \\\"binary\\\",\\n \\\"version\\\": \\\"v1.50.0\\\",\\n \\\"license\\\": \\\"Apache-2.0\\\",\\n \\\"default_binary\\\": \\\"victoria-logs-prod\\\",\\n \\\"binaries\\\": [\\\"victoria-logs-prod\\\", \\\"victoria-logs\\\"],\\n \\\"platforms\\\": {\\n \\\"linux/amd64\\\": {\\n \\\"archive\\\": \\\"tar.gz\\\",\\n \\\"url\\\": \\\"https://github.com/VictoriaMetrics/VictoriaLogs/releases/download/v1.50.0/victoria-logs-linux-amd64-v1.50.0.tar.gz\\\",\\n \\\"sha256\\\": \\\"ab8a4503d88efe62ee72c51da2cf0215890e84ac4f6e1c6ab07d1318972f5ddc\\\",\\n \\\"extract\\\": \\\"victoria-logs-prod\\\"\\n },\\n \\\"darwin/arm64\\\": {\\n \\\"archive\\\": \\\"tar.gz\\\",\\n \\\"url\\\": \\\"https://github.com/VictoriaMetrics/VictoriaLogs/releases/download/v1.50.0/victoria-logs-darwin-arm64-v1.50.0.tar.gz\\\",\\n \\\"sha256\\\": \\\"536edba47c756e398870e418f0cf225604bd17d6a7a6abd899ad9a58f7639b8a\\\",\\n \\\"extract\\\": \\\"victoria-logs-prod\\\"\\n }\\n },\\n \\\"images\\\": [\\n {\\n \\\"ref\\\": \\\"victoriametrics/victoria-logs:v1.50.0\\\",\\n \\\"optional\\\": true,\\n \\\"usage\\\": \\\"dev.observability.logs\\\",\\n \\\"stability\\\": \\\"unstable\\\"\\n }\\n ]\\n },\\n {\\n \\\"name\\\": \\\"victoria-traces\\\",\\n \\\"kind\\\": \\\"binary\\\",\\n \\\"version\\\": \\\"v0.8.1\\\",\\n \\\"license\\\": \\\"Apache-2.0\\\",\\n \\\"default_binary\\\": \\\"victoria-traces-prod\\\",\\n \\\"binaries\\\": [\\\"victoria-traces-prod\\\", \\\"victoria-traces\\\"],\\n \\\"platforms\\\": {\\n \\\"linux/amd64\\\": {\\n \\\"archive\\\": \\\"tar.gz\\\",\\n \\\"url\\\": \\\"https://github.com/VictoriaMetrics/VictoriaTraces/releases/download/v0.8.1/victoria-traces-linux-amd64-v0.8.1.tar.gz\\\",\\n \\\"sha256\\\": \\\"86cb09c1da3f63dedc8a0c4ebb8d30710ff4175c4611dd710ec77f679fdd913a\\\",\\n \\\"extract\\\": \\\"victoria-traces-prod\\\"\\n },\\n \\\"darwin/arm64\\\": {\\n \\\"archive\\\": \\\"tar.gz\\\",\\n \\\"url\\\": \\\"https://github.com/VictoriaMetrics/VictoriaTraces/releases/download/v0.8.1/victoria-traces-darwin-arm64-v0.8.1.tar.gz\\\",\\n \\\"sha256\\\": \\\"459727de68402ed38a59a2ba8271cc331d27a53799add6dfbabaf3bfc4bd3057\\\",\\n \\\"extract\\\": \\\"victoria-traces-prod\\\"\\n }\\n },\\n \\\"images\\\": [\\n {\\n \\\"ref\\\": \\\"victoriametrics/victoria-traces:v0.8.1\\\",\\n \\\"optional\\\": true,\\n \\\"usage\\\": \\\"dev.observability.traces\\\",\\n \\\"stability\\\": \\\"unstable\\\"\\n }\\n ]\\n },\\n {\\n \\\"name\\\": \\\"postgres\\\",\\n \\\"kind\\\": \\\"image\\\",\\n \\\"version\\\": \\\"18\\\",\\n \\\"images\\\": [\\n {\\n \\\"ref\\\": \\\"postgres:18\\\",\\n \\\"optional\\\": true,\\n \\\"usage\\\": \\\"dev.services.postgres\\\",\\n \\\"stability\\\": \\\"unstable\\\"\\n }\\n ]\\n },\\n {\\n \\\"name\\\": \\\"temporal-cli\\\",\\n \\\"kind\\\": \\\"binary\\\",\\n \\\"version\\\": \\\"1.7.0\\\",\\n \\\"license\\\": \\\"MIT\\\",\\n \\\"default_binary\\\": \\\"temporal\\\",\\n \\\"binaries\\\": [\\\"temporal\\\"],\\n \\\"platforms\\\": {\\n \\\"linux/amd64\\\": {\\n \\\"archive\\\": \\\"tar.gz\\\",\\n \\\"url\\\": \\\"https://github.com/temporalio/cli/releases/download/v1.7.0/temporal_cli_1.7.0_linux_amd64.tar.gz\\\",\\n \\\"sha256\\\": \\\"8b5de72e622f4ae062d0d5d948ca398de6212d63b2f25766a1cb810a3dc2d0ed\\\",\\n \\\"extract\\\": \\\"temporal\\\"\\n },\\n \\\"darwin/arm64\\\": {\\n \\\"archive\\\": \\\"tar.gz\\\",\\n \\\"url\\\": \\\"https://github.com/temporalio/cli/releases/download" · [email protected]/internal/toolchain/manifest_gen.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.1.0Review122026-06-13
v0.1.3-0.20260612080544-e24c0b54e85bHigh risk602026-06-13
v0.1.2Review122026-06-13

Block this in CI

PkgRadar gates scenery.sh (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go [email protected]