PkgRadar

Go modules · proxy.golang.org

totogh.173371.xyz/sigstore/cosign

Remote Payload: matched "curl "

Why PkgRadar flagged v1.6.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · totogh.173371.xyz/sigstore/[email protected]/go.mod
mediumRemote Payloadmatched "curl " · totogh.173371.xyz/sigstore/[email protected]/go.sum
mediumRemote Payloadmatched "curl " · totogh.173371.xyz/sigstore/[email protected]/third_party/VENDOR-LICENSE/github.com/hashicorp/vault/api/client.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.13.1Review242026-06-08
v1.6.0High risk362026-06-08
v1.5.1Review122026-06-08
v1.2.0Review122026-06-08
v1.11.1Review242026-06-08
v1.7.0High risk362026-06-08
v1.13.6Low risk02026-06-08

Block this in CI

PkgRadar gates totogh.173371.xyz/sigstore/cosign (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go totogh.173371.xyz/sigstore/[email protected]