PkgRadar

Go modules · proxy.golang.org

github.com/asp3cto/go-ytdlp

Remote Payload: matched "github.com/BtbN/FFmpeg-Builds/releases/download"

Why PkgRadar flagged v0.0.0-20260603195311-55b0c9600980

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/BtbN/FFmpeg-Builds/releases/download" · github.com/asp3cto/[email protected]/install_ffmpeg.go
mediumRemote Payloadmatched "github.com/yt-dlp/yt-dlp/releases/download" · github.com/asp3cto/[email protected]/install_ytdlp.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260603195311-55b0c9600980Review242026-06-04
v0.0.0-20260603191522-e6dde3a45865Review242026-06-04

Block this in CI

PkgRadar gates github.com/asp3cto/go-ytdlp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/asp3cto/[email protected]