PkgRadar

Maven · repo1.maven.org

io.github.gwy2025:gwy2025.spring

Remote Payload: matched "CURL "

Why PkgRadar flagged 1.0.8.2

SeveritySignalEvidence
mediumRemote Payloadmatched "CURL " · com/gotool/service/constant/StarterConstants.java

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.8.2Review122026-06-11

Block this in CI

PkgRadar gates io.github.gwy2025:gwy2025.spring (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven io.github.gwy2025:[email protected]