PkgRadar

Go modules · proxy.golang.org

github.com/astra-sh/qvr

Remote Payload: matched "wget "

Why PkgRadar flagged v0.23.0

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · github.com/astra-sh/[email protected]/internal/security/rules_data.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.23.0Review222026-06-11
v0.22.0Review222026-06-11
v0.20.0Review222026-06-10
v0.19.1Review222026-06-10
v0.8.9Review272026-06-09
v0.4.4Review52026-06-09
v0.10.0Review222026-06-09
v0.8.7Review272026-06-09
v0.8.2Review272026-06-09
v0.8.3Review272026-06-09
v0.8.4Review272026-06-09
v0.8.5Review272026-06-09
v0.8.6Review272026-06-09
v0.16.4Review222026-06-09
v0.10.1Review222026-06-09

Block this in CI

PkgRadar gates github.com/astra-sh/qvr (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/astra-sh/[email protected]