PkgRadar

Go modules · proxy.golang.org

github.com/Steveyegge/beads

Remote Payload

Why PkgRadar flagged v0.30.0

SeveritySignalEvidence
mediumRemote Payloadgithub.com/steveyegge/[email protected]/cmd/bd/doctor/claude.go
mediumRemote Payloadgithub.com/steveyegge/[email protected]/cmd/bd/init.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.30.0Review242026-06-22
v0.15.0Low risk02026-06-22
v1.0.1Review242026-06-22
v1.0.2Review242026-06-22
v0.63.0Review242026-06-22
v0.30.7Review242026-06-22
v0.45.0Review242026-06-22
v0.39.0Review242026-06-22
v0.55.0Review242026-06-22
v0.38.0Review242026-06-22
v0.30.2Review242026-06-22
v0.21.2Review122026-06-22
v0.24.4Review242026-06-22
v0.9.3Low risk02026-06-22
v0.50.0Review242026-06-22
v0.16.0Low risk02026-06-22
v0.30.1Review242026-06-22
v0.9.2Low risk02026-06-22
v0.49.1Review242026-06-22
v0.30.6Review242026-06-22
v0.24.3Review242026-06-22
v0.9.4Low risk02026-06-22
v0.40.0Review242026-06-22
v0.58.0Review242026-06-22
v0.59.0Review242026-06-22
v0.63.2Review242026-06-22
v0.50.2Review242026-06-22
v1.0.6-0.20260621034415-4d08edbeb772Review242026-06-22
v0.17.7Low risk02026-06-22
v1.0.5Review242026-06-22
v0.9.11Low risk02026-06-22

Block this in CI

PkgRadar gates github.com/Steveyegge/beads (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/Steveyegge/[email protected]