PkgRadar

Go modules · proxy.golang.org

github.com/alexellis/arkade

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged v0.0.0-20260616170619-db87cbea02bb

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/alexellis/[email protected]/cmd/apps/argocd_app.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/alexellis/[email protected]/cmd/apps/kube_image_prefetch_app.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/alexellis/[email protected]/cmd/apps/metallb_app.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/alexellis/[email protected]/cmd/apps/openfaas_app.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/alexellis/[email protected]/cmd/apps/openfaas_ce_app.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/alexellis/[email protected]/cmd/apps/registry_creds_app.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/alexellis/[email protected]/cmd/system/caddy.go
mediumRemote Payloadmatched "github.com/%s/%s/releases/download" · github.com/alexellis/[email protected]/cmd/system/common.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/alexellis/[email protected]/cmd/system/containerd.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/alexellis/[email protected]/cmd/system/zvol_snapshotter.go
mediumRemote Payloadmatched "github.com/%s/%s/releases/download" · github.com/alexellis/[email protected]/pkg/get/get.go
mediumRemote Payloadmatched "github.com/micahkepe/jsongrep/releases/download" · github.com/alexellis/[email protected]/pkg/get/tools.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260616170619-db87cbea02bbHigh risk862026-06-17
v0.0.0-20200819082422-612c2aff2b8eHigh risk1002026-06-15
v0.0.0-20210130153302-6680f8346be4High risk862026-06-15
v0.0.0-20200823091456-0906524ac183High risk1002026-06-15
v0.0.0-20200809195648-05b03a112e82High risk1002026-06-15
v0.0.0-20200806164236-8de0eff4feb0High risk1002026-06-15
v0.0.0-20200701185943-e0f2b4094a81High risk1002026-06-15
v0.0.0-20200721084130-531ac43b4cb0High risk1002026-06-15
v0.0.0-20210213082718-6a810bf2d441High risk862026-06-15
v0.0.0-20210213082954-2af6cb64ba6aHigh risk862026-06-15
v0.0.0-20210206194206-140eec96c0f1High risk862026-06-15
v0.0.0-20210601130118-a2baa0f3849aHigh risk862026-06-14

Block this in CI

PkgRadar gates github.com/alexellis/arkade (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/alexellis/[email protected]