PkgRadar

Go modules · proxy.golang.org

github.com/MD-Mushfiqur123/lychee

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v0.20.4-rc0

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/md-mushfiqur123/[email protected]/ml/backend/ggml/ggml/src/ggml-metal/metal.go
mediumRemote Payloadmatched "curl " · github.com/md-mushfiqur123/[email protected]/server/inference_request_log.go
mediumRemote Payloadmatched "curl " · github.com/md-mushfiqur123/[email protected]/x/agent/approval.go
mediumRemote Payloadmatched "cURL " · github.com/md-mushfiqur123/[email protected]/x/imagegen/transfer/upload.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.5.8-rc1Review152026-06-17
v0.20.4-rc0High risk562026-06-17
v0.25.0-rc0High risk682026-06-17
v0.5.2-rc3Low risk02026-06-17
v0.30.0-rc30High risk532026-06-17
v0.22.0High risk802026-06-17
v0.1.39-rc2Review452026-06-17
v0.11.1Review152026-06-17
v0.3.7-rc2Review452026-06-17
v0.12.4-rc7Review152026-06-17
v0.1.45Review452026-06-17
v0.13.4-rc0Review152026-06-17
v0.14.0Review442026-06-17
v0.2.2Review452026-06-17
v0.15.5-rc3Review442026-06-17
v0.11.4-rc0Review152026-06-17
v0.5.13-rc6Review152026-06-17
v0.5.5-rc0Low risk02026-06-17
v0.30.3High risk652026-06-17
v0.5.8-rc12Review152026-06-17
v0.14.3Review442026-06-17
v0.1.49-rc2Review452026-06-17
v0.4.5Low risk02026-06-17
v0.1.49-rc7Review452026-06-17
v0.1.34-rc1Review452026-06-17
v0.4.0-rc2Low risk02026-06-17
v0.30.4High risk652026-06-17
v0.17.8-rc0Review592026-06-17
v0.14.1Review442026-06-17
v0.12.5Review152026-06-17
v0.13.2-rc1Review152026-06-17
v0.9.3-rc2Review152026-06-17
v0.1.13Low risk02026-06-17
v0.3.11-rc3Review452026-06-17
v0.3.2Review452026-06-17
v0.30.2-rc0High risk652026-06-17
v0.14.0-rc1Review442026-06-17
v0.12.4-rc2Review152026-06-17
v0.4.4Low risk02026-06-17
v0.12.6Review152026-06-17
v0.12.4-rc3Review152026-06-17
v0.6.1Review152026-06-17
v0.17.7Review592026-06-17
v0.3.11Review452026-06-17
v0.2.7Review452026-06-17
v0.12.1-rc1Review152026-06-17
v0.12.7-citest0Review152026-06-17
v0.1.29Review302026-06-17
v0.1.39-rc1Review452026-06-17
v0.6.4Review152026-06-17
v0.20.6-rc0High risk562026-06-17
v0.14.0-rc3Review442026-06-17
v0.10.0-rc4Review152026-06-17
v0.2.2-rc1Review452026-06-17
v0.30.0-rc12High risk532026-06-17
v0.30.0-rc6High risk652026-06-17
v0.1.45-rc5Review452026-06-17
v0.1.33-rc1Review452026-06-17
v0.14.3-rc0Review442026-06-17
v0.5.13Review152026-06-17
v0.7.0-rc0Review152026-06-17
v0.15.0-rc5Review442026-06-17
v0.9.0Review152026-06-17
v0.24.0-rc1High risk682026-06-17
v0.1.37Review452026-06-17
v0.12.2Review152026-06-17
v0.15.5-rc1Review442026-06-17
v0.20.1-rc1High risk562026-06-17
v0.30.0-rc1High risk652026-06-17
v0.21.1High risk802026-06-17
v0.1.0Low risk02026-06-17
v0.20.5-rc0High risk562026-06-17
v0.14.0-rc11Review442026-06-17
v0.21.0High risk682026-06-17
v0.1.14Low risk02026-06-17
v0.4.7Low risk02026-06-17
v0.12.4-rc4Review152026-06-17
v0.16.3Review592026-06-17
v0.1.5Low risk02026-06-17
v0.1.33-rc6Review452026-06-17
v0.2.8Review452026-06-17
v0.3.12-rc4Review452026-06-17
v0.30.0-rc3High risk652026-06-17
v0.7.1-rc0Review152026-06-17
v0.30.0-rc0High risk652026-06-17
v0.15.0-rc0Review442026-06-17
v0.17.1-rc0Review592026-06-17
v0.11.2Review152026-06-17
v0.9.4-citest0Review152026-06-17
v0.13.1-rc0Review152026-06-17
v0.6.3-rc0Review152026-06-17
v0.12.11-rc0Review152026-06-17
v0.1.35Review452026-06-17
v0.13.2-rc2Review152026-06-17
v0.21.2-rc0High risk802026-06-17
v0.12.0Review152026-06-17
v0.1.34Review452026-06-17
v0.18.3-rc0High risk562026-06-17
v0.4.0-rc3Low risk02026-06-17
v0.18.3-rc1High risk562026-06-17
v0.30.4-rc1High risk652026-06-17
v0.12.4-rc0Review152026-06-17
v0.30.0-rc19High risk532026-06-17
v0.10.0-rc0Review152026-06-17
v0.17.8-rc3Review442026-06-17
v0.5.3-rc0Low risk02026-06-17
v0.1.10Low risk02026-06-17
v0.23.3High risk682026-06-17
v0.13.0-rc0Review152026-06-17
v0.0.18Low risk02026-06-17
v0.3.7-rc6Review452026-06-17
v0.13.2Review152026-06-17
v0.3.14Review452026-06-17
v0.3.13Review452026-06-17
v0.18.3High risk562026-06-17
v0.30.0-rc5High risk652026-06-17
v0.18.4-rc0High risk562026-06-17
v0.1.27Review302026-06-17
v0.5.2-rc0Low risk02026-06-17
v0.6.5-rc1Review152026-06-17
v0.6.6-rc0Review152026-06-17
v0.5.8-rc10Review152026-06-17
v0.6.3-rc1Review152026-06-17
v0.5.13-rc0Review152026-06-17
v0.30.0-rc31High risk532026-06-17
v0.1.49-rc9Review452026-06-17
v0.11.6Review152026-06-17
v0.23.3-rc1High risk682026-06-17
v0.20.0-rc1High risk562026-06-17
v0.5.8-rc13Review152026-06-17
v0.19.0-rc1High risk562026-06-17
v0.4.0-ci3Low risk02026-06-17
v0.9.3-rc3Review152026-06-17
v0.17.1-rc1Review592026-06-17
v0.3.12-rc3Review452026-06-17
v0.20.3High risk562026-06-17
v0.24.0-rc0High risk682026-06-17
v0.11.11Review152026-06-17
v0.1.36Review452026-06-17
v0.12.8-rc0Review152026-06-17
v0.1.23Review302026-06-17
v0.11.6-rc0Review152026-06-17
v0.13.3-rc0Review152026-06-17
v0.5.8-rc7Review152026-06-17
v0.5.11Review152026-06-17
v0.20.0-rc0High risk562026-06-17
v0.30.5High risk652026-06-17
v0.11.0-rc2Review152026-06-17
v0.5.12-rc1Review152026-06-17
v0.0.16Low risk02026-06-17
v0.12.9Review152026-06-17
v0.0.4Low risk02026-06-17
v0.30.0-rc27High risk532026-06-17
v0.12.1-rc2Review152026-06-17
v0.1.49-rc13Review452026-06-17
v0.22.1-rc0High risk802026-06-17
v0.1.45-rc1Review452026-06-17
v0.16.0-rc0Review592026-06-17
v0.7.0-rc1Review152026-06-17
v0.15.0-rc6Review442026-06-17
v0.1.26Review302026-06-17
v0.1.1Low risk02026-06-17
v0.12.0-rc0Review152026-06-17
v0.5.0-alphaHigh risk842026-06-17
v0.1.35-rc1Review452026-06-17
v0.12.7-rc1Review152026-06-17
v0.6.4-rc0Review152026-06-17
v0.15.3Review442026-06-17
v0.2.0Review452026-06-17
v0.3.10Review452026-06-17
v0.13.1-rc1Review152026-06-17
v0.3.11-rc1Review452026-06-17
v0.6.5Review152026-06-17
v0.20.5High risk562026-06-17
v0.6.7-rc0Review152026-06-17
v0.8.0Review152026-06-17
v0.23.2High risk802026-06-17
v0.11.5-rc2Review152026-06-17
v0.20.7-rc1High risk562026-06-17
v0.12.8Review152026-06-17
v0.1.49-rc12Review452026-06-17
v0.15.0-rc4Review442026-06-17
v0.16.0-rc2Review592026-06-17
v0.1.22Review302026-06-17
v0.1.47Review452026-06-17
v0.20.7-rc0High risk562026-06-17
v0.18.2-rc1Review442026-06-17
v0.5.12Review152026-06-17
v0.1.43Review452026-06-17
v0.3.6Review452026-06-17
v0.5.12-rc0Review152026-06-17
v0.5.8-rc6Review152026-06-17
v0.17.7-rc0Review592026-06-17
v0.12.11-rc1Review152026-06-17
v0.1.21Review302026-06-17
v0.20.4-rc2High risk562026-06-17
v0.5.8-rc3Review152026-06-17
v0.11.9Review152026-06-17
v0.2.5Review452026-06-17
v0.1.30Review302026-06-17

Block this in CI

PkgRadar gates github.com/MD-Mushfiqur123/lychee (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/MD-Mushfiqur123/[email protected]