PkgRadar

Go modules · proxy.golang.org

github.com/artifactHub/hub

Remote Payload, Credential file access

Why PkgRadar flagged v1.22.1-0.20260512181917-0d8b1c0b9f6b

SeveritySignalEvidence
mediumRemote Payloadgithub.com/artifacthub/[email protected]/internal/handlers/static/handlers.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.22.1-0.20260512181917-0d8b1c0b9f6bReview152026-06-21
v0.16.0Review242026-06-21
v1.22.0Review152026-06-21

Block this in CI

PkgRadar gates github.com/artifactHub/hub (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/artifactHub/[email protected]