PkgRadar

Go modules · proxy.golang.org

github.com/Azure/unbounded

Remote Payload: matched "github.com/containerd/containerd/releases/download"

Why PkgRadar flagged v0.1.15

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/containerd/containerd/releases/download" · github.com/azure/[email protected]/cmd/kubectl-unbounded/app/machine_manual_bootstrap.go
mediumRemote Payloadmatched "github.com/containerd/containerd/releases/download" · github.com/azure/[email protected]/cmd/kubectl-unbounded/app/machine_register.go
mediumRemote Payloadmatched "curl " · github.com/azure/[email protected]/cmd/kubectl-unbounded/app/net/proxy.go
mediumRemote Payloadmatched "github.com/containernetworking/plugins/releases/download" · github.com/azure/[email protected]/pkg/agent/phases/rootfs/cni.go
mediumRemote Payloadmatched "github.com/containerd/containerd/releases/download" · github.com/azure/[email protected]/pkg/agent/phases/rootfs/cri.go
mediumRemote Payloadmatched "github.com/kubernetes-sigs/cri-tools/releases/download" · github.com/azure/[email protected]/pkg/agent/phases/rootfs/kube.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.1.15High risk722026-06-13
v0.1.14High risk722026-06-12
v0.1.13High risk722026-06-06
v0.1.12-0.20260604213411-18bd40b72ec5High risk722026-06-06
v0.1.12High risk722026-06-06
v0.1.11High risk722026-06-05
v0.1.11-0.20260602204255-7e1a30675953High risk722026-06-04
v0.1.10High risk722026-06-02
v0.1.9-0.20260527152121-69be6a54e174High risk722026-05-30

Block this in CI

PkgRadar gates github.com/Azure/unbounded (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/Azure/[email protected]