Go modules · proxy.golang.org
github.com/aflock-ai/rookery/plugins/attestors/sarif
Go Mod Replace Local: go.mod replace directive redirects to a local filesystem path — non-portable / dev-time only.
Why PkgRadar flagged v0.0.0-20260611183525-7b391b683ea6
| Severity | Signal | Evidence |
|---|---|---|
| medium | Go Mod Replace Local | go.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/aflock-ai/rookery/plugins/attestors/[email protected]/go.mod |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v0.0.0-20260611183525-7b391b683ea6 | Review | 10 | 2026-06-12 |
v0.0.0-20260610200930-69d9422b8392 | Review | 10 | 2026-06-11 |
v0.0.0-20260603142341-7688ddeeb424 | Review | 10 | 2026-06-04 |
v0.0.0-20260529001459-3cf205798022 | Review | 10 | 2026-05-30 |
v0.0.0-20260528015427-dadc8fd9d5c7 | Review | 10 | 2026-05-29 |
Block this in CI
pkgradar gate --ecosystem go github.com/aflock-ai/rookery/plugins/attestors/[email protected]