PkgRadar

Go modules · proxy.golang.org

github.com/ava-labs/avalanchego/graft/coreth

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v1.14.3-0.20260609004932-345fdfaa749b

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/ava-labs/avalanchego/graft/[email protected]/plugin/evm/compile.go
mediumRemote Payloadmatched "curl " · github.com/ava-labs/avalanchego/graft/[email protected]/go.sum

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.14.3-0.20260609004932-345fdfaa749bReview272026-06-10
v1.14.3-0.20260603151011-1339ef45dc6cReview272026-06-10
v1.14.3-0.20260602193739-919446e8501fReview272026-06-05
v1.14.3-0.20260603174913-47c06ddd6529Review272026-06-04
v1.14.3-0.20260603133342-15a574a27d75Review272026-06-04
v1.14.3-0.20260603163712-fb174e8925baReview272026-06-04
v1.14.3-0.20260602150254-74e4738be230Review272026-06-03
v1.14.3-0.20260528202939-89ac856f8755Review272026-06-01
v0.0.0-20260528202939-89ac856f8755Review272026-06-01

Block this in CI

PkgRadar gates github.com/ava-labs/avalanchego/graft/coreth (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/ava-labs/avalanchego/graft/[email protected]