PkgRadar

Go modules · proxy.golang.org

github.com/amarbel-llc/purse-first

Remote Payload: matched "github.com/%s/releases/download"

Why PkgRadar flagged v0.2.6-0.20260530121752-67a6f4d5e72d

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/%s/releases/download" · github.com/amarbel-llc/[email protected]/internal/packagebrew/formula.go
mediumRemote Payloadmatched "github.com/([^/]+)/([^/]+)/releases/download" · github.com/amarbel-llc/[email protected]/internal/packagebrew/strategy.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.3.1-0.20260611180528-00c193ed49b4Low risk02026-06-13
v0.3.2Low risk02026-06-13
v0.3.1Low risk02026-06-08
v0.3.1-0.20260607232245-8c4b12e3b8e0Low risk02026-06-08
v0.3.1-0.20260607231336-dfb31b548661Low risk02026-06-08
v0.3.1-0.20260607010611-a5b2690fa92cLow risk02026-06-08
v0.2.10-0.20260606215331-51e69a84184eLow risk02026-06-07
v0.3.0Low risk02026-06-07
v0.2.10-0.20260604221323-21d328cce0f4Low risk02026-06-06
v0.2.9Low risk02026-06-06
v0.2.8-0.20260601003227-a8322cd9ecceLow risk02026-06-02
v0.2.7Low risk02026-06-02
v0.2.8Low risk02026-06-02
v0.2.6-0.20260530121752-67a6f4d5e72dReview242026-06-01
v0.2.7-0.20260531114242-39fbd2a9eb82Review242026-06-01
v0.2.6Review242026-06-01
v0.2.6-0.20260529122707-22fa2410dc79Review242026-05-30
v0.2.5Review242026-05-30
v0.2.4-0.20260528095941-07a2a0a16dacReview292026-05-29
v0.2.4-0.20260527094812-f9b9b60436fbReview292026-05-29
v0.2.4-0.20260527134358-fd4074b6304bReview292026-05-29

Block this in CI

PkgRadar gates github.com/amarbel-llc/purse-first (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/amarbel-llc/[email protected]