PkgRadar

Go modules · proxy.golang.org

github.com/89luca89/distrobox

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged v0.0.0-20260605174820-e251b5e5a508

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/89luca89/[email protected]/internal/cli/compatibility.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/89luca89/[email protected]/pkg/commands/distro_icons.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/89luca89/[email protected]/pkg/commands/generate_entry.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260605174820-e251b5e5a508High risk362026-06-06
v0.0.0-20260527072642-d02374e14a1bReview242026-06-03
v0.0.0-20260527131931-964099b8cecbLow risk02026-06-03

Block this in CI

PkgRadar gates github.com/89luca89/distrobox (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/89luca89/[email protected]