PkgRadar

Go modules · proxy.golang.org

toredirect-togh.173371.xyz/slsa-framework/slsa-github-generator

Remote Payload: matched "curl "

Why PkgRadar flagged v1.3.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · toredirect-togh.173371.xyz/slsa-framework/[email protected]/go.mod
mediumRemote Payloadmatched "curl " · toredirect-togh.173371.xyz/slsa-framework/[email protected]/go.sum

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.7.0-rc.0Low risk02026-06-15
v1.10.0-rc.0Low risk02026-06-15
v1.8.0Low risk02026-06-15
v1.6.0-rc.1Low risk02026-06-15
v1.9.0Low risk02026-06-15
v1.3.0Review242026-06-15
v1.6.0Low risk02026-06-15
v1.4.0-rc.1Review242026-06-15
v1.0.0Review242026-06-15
v1.2.1Review242026-06-15
v1.6.0-rc.0Review242026-06-15
v1.4.0Review242026-06-15
v1.8.0-rc.2Low risk02026-06-15
v1.6.0-rc.2Low risk02026-06-15
v1.7.0-rc.1Low risk02026-06-15
v1.2.0Review242026-06-15
v1.8.0-rc.0Low risk02026-06-15
v1.4.0-rc.2Review242026-06-15
v1.1.1Review242026-06-15
v1.2.2Review242026-06-15
v1.5.0Review242026-06-15
v1.6.0-rc.3Low risk02026-06-15
v1.9.1Low risk02026-06-15
v1.9.0-rc.0Low risk02026-06-15
v1.8.0-rc.1Low risk02026-06-15
v1.4.0-rc.0Review242026-06-15
v1.10.1-0.20260309230332-4d014fae4dbdLow risk02026-06-15
v1.1.0Review242026-06-15
v1.10.0Low risk02026-06-15

Block this in CI

PkgRadar gates toredirect-togh.173371.xyz/slsa-framework/slsa-github-generator (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go toredirect-togh.173371.xyz/slsa-framework/[email protected]