PkgRadar

Go modules · proxy.golang.org

yunion.io/x/onecloud

Remote Payload: matched "cUrl "

Why PkgRadar flagged v0.0.0-20260609150204-44f7c6e68845

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · yunion.io/x/[email protected]/cmd/climc/shell/misc/pprof.go
mediumRemote Payloadmatched "cUrl " · yunion.io/x/[email protected]/pkg/apis/compute/storagecache.go
mediumRemote Payloadmatched "cUrl " · yunion.io/x/[email protected]/pkg/apis/llm/llm.go
mediumRemote Payloadmatched "wGet " · yunion.io/x/[email protected]/pkg/cloudcommon/db/rbac.go
mediumRemote Payloadmatched "curl " · yunion.io/x/[email protected]/pkg/compute/misc/handler.go
mediumRemote Payloadmatched "curl " · yunion.io/x/[email protected]/pkg/compute/models/hosts.go
mediumRemote Payloadmatched "cUrl " · yunion.io/x/[email protected]/pkg/compute/models/vpcs.go
mediumRemote Payloadmatched "cUrl " · yunion.io/x/[email protected]/pkg/hostman/storageman/imagecachemanager_agent.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · yunion.io/x/[email protected]/pkg/keystone/driver/oidc/class.go
mediumRemote Payloadmatched "cURL " · yunion.io/x/[email protected]/pkg/keystone/models/endpoints.go
mediumRemote Payloadmatched "cUrl " · yunion.io/x/[email protected]/pkg/llm/models/llm.go
mediumRemote Payloadmatched "cURL " · yunion.io/x/[email protected]/pkg/mcclient/token2.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260609150204-44f7c6e68845High risk1102026-06-11
v0.0.0-20260605112819-e0584f12e3adHigh risk1102026-06-08
v0.0.0-20260424034553-0c6a3770b597High risk1102026-06-08
v0.0.0-20260601075244-d20f102508c3High risk1102026-06-02
v0.0.0-20260202123808-55c139f4ab2cHigh risk1102026-06-02

Block this in CI

PkgRadar gates yunion.io/x/onecloud (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go yunion.io/x/[email protected]