PkgRadar

Go modules · proxy.golang.org

github.com/Sap/jenkins-library

Remote Payload: matched "github.com/anchore/syft/releases/download"

Why PkgRadar flagged v1.507.1-0.20260605090658-8cf85b20b0c7

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/anchore/syft/releases/download" · github.com/sap/[email protected]/cmd/cnbBuild_generated.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/sap/[email protected]/cmd/credentialdiggerScan_generated.go
mediumRemote Payloadmatched "github.com/golangci/golangci-lint/releases/download" · github.com/sap/[email protected]/cmd/golangBuild_generated.go
mediumRemote Payloadmatched "github.com/anchore/syft/releases/download" · github.com/sap/[email protected]/cmd/kanikoExecute_generated.go
mediumRemote Payloadmatched "github.com/SAP/SapMachine/releases/download" · github.com/sap/[email protected]/cmd/whitesourceExecuteScan_generated.go
mediumRemote Payloadmatched "github.com/CycloneDX/cyclonedx-cli/releases/download" · github.com/sap/[email protected]/pkg/npm/bom.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.507.1-0.20260605090658-8cf85b20b0c7High risk882026-06-07
v1.507.0High risk882026-06-07

Block this in CI

PkgRadar gates github.com/Sap/jenkins-library (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/Sap/[email protected]