Go modules · proxy.golang.org
gitee.com/vaf/baml
Remote Payload: matched "github.com/%s/releases/download"
Why PkgRadar flagged v0.88.0
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "github.com/%s/releases/download" · gitee.com/vaf/[email protected]/engine/language_client_go/baml_go/lib.go |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v0.88.0 | Review | 12 | 2026-06-12 |
v0.221.0 | Review | 12 | 2026-06-12 |
v0.87.1 | Review | 12 | 2026-06-12 |
v0.85.0 | Review | 12 | 2026-06-12 |
v0.86.1 | Review | 12 | 2026-06-12 |
v0.200.0 | Review | 12 | 2026-06-12 |
v0.220.0 | Review | 12 | 2026-06-12 |
v0.34.0 | Low risk | 0 | 2026-06-12 |
v0.211.0 | Review | 12 | 2026-06-12 |
v0.214.0 | Review | 12 | 2026-06-12 |
v0.218.0 | Review | 12 | 2026-06-12 |
v0.207.1 | Review | 12 | 2026-06-12 |
v0.208.5 | Review | 12 | 2026-06-12 |
v0.219.0 | Review | 12 | 2026-06-12 |
v0.215.0 | Review | 12 | 2026-06-12 |
Block this in CI
pkgradar gate --ecosystem go gitee.com/vaf/[email protected]