PkgRadar

Go modules · proxy.golang.org

tangled.org/core

Remote Payload: matched "CURL "

Why PkgRadar flagged v0.0.0-20260612103734-ff6d47cfb983

SeveritySignalEvidence
mediumRemote Payloadmatched "CURL " · tangled.org/[email protected]/appview/config/config.go
mediumRemote Payloadmatched "cURL " · tangled.org/[email protected]/appview/repo/archive.go
mediumRemote Payloadmatched "cUrl " · tangled.org/[email protected]/idresolver/resolver.go
mediumRemote Payloadmatched "cUrl " · tangled.org/[email protected]/knotmirror/config/config.go
mediumRemote Payloadmatched "cUrl " · tangled.org/[email protected]/knotserver/config/config.go
mediumRemote Payloadmatched "cUrl " · tangled.org/[email protected]/knotserver/repodid/repodid.go
mediumRemote Payloadmatched "cUrl " · tangled.org/[email protected]/spindle/config/config.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260612103734-ff6d47cfb983High risk842026-06-13
v1.0.3-alpha.0.20250405114757-c2e3b7a7a14fLow risk02026-05-30
v1.14.1-alpha.0.20260528232853-0ce6a113ba34Review842026-05-30

Block this in CI

PkgRadar gates tangled.org/core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go tangled.org/[email protected]