PkgRadar

Go modules · proxy.golang.org

github.com/Supabase/cli

Reverse Shell

Why PkgRadar flagged v1.47.2

SeveritySignalEvidence
highReverse Shellgithub.com/supabase/[email protected]/internal/start/start.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.4.3Review52026-06-23
v1.10.0Review52026-06-23
v1.47.2High risk402026-06-23
v1.7.6Review52026-06-23
v1.188.3Low risk02026-06-23
v1.115.4High risk522026-06-23
v1.42.5High risk402026-06-23
v1.145.3High risk522026-06-23
v1.8.4Review52026-06-23
v1.176.0Low risk02026-06-23
v1.52.3High risk402026-06-23
v1.68.0High risk522026-06-23
v1.8.5Review52026-06-23
v1.125.0High risk522026-06-23
v1.47.1High risk402026-06-23
v1.162.7High risk522026-06-23
v1.27.0Low risk02026-06-23
v1.226.0Low risk02026-06-23
v1.176.2Low risk02026-06-23
v1.105.0High risk522026-06-23
v1.176.6Low risk02026-06-23
v1.139.0High risk522026-06-23
v1.155.2High risk522026-06-23
v1.207.9Low risk02026-06-23
v1.224.1Low risk02026-06-23
v0.39.0Low risk02026-06-23
v1.24.0Low risk02026-06-23
v1.26.5Low risk02026-06-23
v0.12.3Low risk02026-06-23
v0.21.1Low risk02026-06-23
v1.54.1High risk402026-06-23
v0.38.0Low risk02026-06-23
v1.42.6High risk402026-06-23
v1.109.1High risk522026-06-23
v0.6.0Low risk02026-06-23
v1.198.3Low risk02026-06-23
v1.43.1High risk402026-06-23
v0.33.0Low risk02026-06-23
v1.138.4High risk522026-06-23
v1.26.8Low risk02026-06-23
v1.110.2High risk522026-06-23
v1.150.2High risk522026-06-23
v0.15.12Low risk02026-06-23
v1.220.1Low risk02026-06-23
v1.99.3High risk522026-06-23
v0.24.4Low risk02026-06-23
v1.192.6Low risk02026-06-23
v1.179.0Low risk02026-06-23
v1.8.6Review52026-06-23
v1.45.1High risk402026-06-23
v1.128.1High risk522026-06-23
v0.29.1Low risk02026-06-23
v1.80.0High risk522026-06-23
v1.90.0High risk522026-06-23
v1.100.0High risk522026-06-23
v1.110.0High risk522026-06-23
v2.107.0+incompatibleLow risk02026-06-23
v1.149.0High risk522026-06-23
v1.148.0High risk522026-06-23
v1.145.0High risk522026-06-23
v1.38.6High risk402026-06-23
v1.130.0High risk522026-06-23
v1.200.0Low risk02026-06-23
v1.140.0High risk522026-06-23
v1.135.0High risk522026-06-23
v1.142.0High risk522026-06-23
v1.120.0High risk522026-06-23
v1.195.0Low risk02026-06-23
v1.190.0Low risk02026-06-23
v1.187.0Low risk02026-06-23
v1.185.0Low risk02026-06-23
v1.183.0Low risk02026-06-23
v1.175.0Review122026-06-23
v1.180.0Low risk02026-06-23
v1.170.0High risk522026-06-23
v1.172.0High risk522026-06-23
v1.167.0High risk522026-06-23
v1.160.0High risk522026-06-23
v1.163.0High risk522026-06-23
v1.165.0High risk522026-06-23
v1.150.0High risk522026-06-23
v1.226.5Low risk02026-06-23

Block this in CI

PkgRadar gates github.com/Supabase/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/Supabase/[email protected]