SafeDep
Install GitHub App

Summary

Multiple low confidence YARA matches found, but no strong evidence to classify package as malware. Likely false positives.

Verification Record

No verification record available.

Details

The package golang.org/x/net version 0.47.0 has multiple YARA rule matches, but all of them are of low confidence. The matches include hardcoded_analytics, foreign_object_script, hardcoded_ip_port, js_hex_obfuscation, possible_dropper, and very_high_entropy. These rules can have legitimate use cases, especially in test data, documentation, and build-related files. The presence of a Dockerfile and test data files makes the possible_dropper and foreign_object_script matches less suspicious. Therefore, there is no strong evidence to classify this package as malware.

golang.org/x/net@0.47.0Clean
Unverified
Analysed at: 11/20/25, 1:43 AM
Source: https://proxy.golang.org/golang.org%2fx%2fnet/@v/v0.47.0.zip
SHA256: 3444c04eff1dc7a41a6386cb6a0b0b1facebfc7e222bae523043ed4b14039f76
Confidence: Medium