PkgRadar

Go modules · proxy.golang.org

sigs.k8s.io/gateway-api

Remote Payload: matched "curl "

Why PkgRadar flagged v1.3.1-0.20260527215245-e3aaefe20ed7

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · sigs.k8s.io/[email protected]/hack/update-protos.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.2.1-0.20210222080530-9d63656df8ccLow risk02026-06-13
v1.3.1-0.20260609191950-0d36be15c005Low risk02026-06-11
v0.0.0-20260603215946-66339b25ef88Low risk02026-06-06
v1.3.1-0.20260603215946-66339b25ef88Low risk02026-06-05
v1.3.1-0.20260602140351-d7fcb0de5672Low risk02026-06-03
v1.3.1-0.20260530040447-124954708648Low risk02026-05-31
v0.0.0-20260518223501-3e4ef89ce6d9Low risk02026-05-30
v0.0.0-20260527210848-cf34ac933d06Low risk02026-05-30
v0.0.0-20260527215245-e3aaefe20ed7Low risk02026-05-30
v1.3.1-0.20260528172054-4f4b4d036125Low risk02026-05-30
v1.3.1-0.20260528213649-c65b5fdf73beLow risk02026-05-30
v1.3.1-0.20260527215245-e3aaefe20ed7Review122026-05-29

Block this in CI

PkgRadar gates sigs.k8s.io/gateway-api (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go sigs.k8s.io/[email protected]