PkgRadar

Go modules · proxy.golang.org

github.com/aaron70/decoy-cli

Go Mod Replace Local: go.mod replace directive redirects to a local filesystem path — non-portable / dev-time only.

Why PkgRadar flagged v0.0.0-20260614212944-10e8d6ccb336

SeveritySignalEvidence
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/aaron70/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260614212944-10e8d6ccb336Review102026-06-16
v0.0.0-20260608050618-0564830cbcd0Low risk02026-06-14
v0.0.0-20260608034708-5d2234c93ea7Low risk02026-06-09
v0.0.0-20260529053511-61d22e7bc21fLow risk02026-05-30
v0.0.0-20260529043944-965c373d06f0Low risk02026-05-30
v0.0.0-20260529032625-9e724bd9efadLow risk02026-05-30

Block this in CI

PkgRadar gates github.com/aaron70/decoy-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/aaron70/[email protected]
github.com/aaron70/decoy-cli — Go modules security scan | PkgRadar