PkgRadar

Go modules · proxy.golang.org

github.com/amazon-contributing/opentelemetry-collector-contrib

Go Mod Replace Local

Why PkgRadar flagged v0.0.0-20231020163023-8bdf732d320a

SeveritySignalEvidence
mediumGo Mod Replace Localgithub.com/amazon-contributing/opentelemetry-collector-contrib@v0.0.0-20231020163023-8bdf732d320a/go.mod

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20231020163023-8bdf732d320aReview102026-06-24
v0.0.0-20260617191712-c832128007a1Low risk02026-06-18
v0.0.0-20260617045644-ef1e2fcbdd98Low risk02026-06-18
v0.0.0-20260615210908-52e153013d81Low risk02026-06-16
v0.0.0-20260612195210-e7ab053ef06dLow risk02026-06-13
v0.0.0-20250612002101-e5d8b9cf3e97Low risk02026-06-13
v0.0.0-20260610175509-69af159e720aLow risk02026-06-11
v0.0.0-20260610140643-d0008160f8b1Low risk02026-06-11
v0.0.0-20260605184720-080071002697Low risk02026-06-06
v0.0.0-20260604150420-c082831a8accLow risk02026-06-05

Block this in CI

PkgRadar gates github.com/amazon-contributing/opentelemetry-collector-contrib (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/amazon-contributing/opentelemetry-collector-contrib@v0.0.0-20231020163023-8bdf732d320a