PkgRadar

Go modules · proxy.golang.org

codeberg.org/kukichalang/kukicha

Remote Payload: matched "github.com/%s/releases/download"

Why PkgRadar flagged v0.0.0-20260605233322-45c2bde9f8a4

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/%s/releases/download" · codeberg.org/kukichalang/[email protected]/cmd/genmanifest/main.go
mediumRemote Payloadmatched "github.com/kukichalang/kukicha/releases/download" · codeberg.org/kukichalang/[email protected]/internal/toolchain/install.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.50.2Low risk02026-06-08
v0.50.2-0.20260606020053-eecd8eb56690Low risk02026-06-07
v0.50.1Low risk02026-06-07
v0.50.0Low risk02026-06-07
v0.0.0-20260605233322-45c2bde9f8a4Review242026-06-06

Block this in CI

PkgRadar gates codeberg.org/kukichalang/kukicha (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go codeberg.org/kukichalang/[email protected]