PkgRadar

Go modules · proxy.golang.org

github.com/ava-labs/avalanchego/graft/evm

Remote Payload: matched "curl "

Why PkgRadar flagged v1.14.3-0.20260609004932-345fdfaa749b

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/ava-labs/avalanchego/graft/[email protected]/go.sum
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/ava-labs/avalanchego/graft/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.14.3-0.20260609004932-345fdfaa749bReview222026-06-10
v1.14.3-0.20260602193739-919446e8501fReview222026-06-05
v1.14.3-0.20260603174913-47c06ddd6529Review222026-06-04
v1.14.3-0.20260603133342-15a574a27d75Review222026-06-04
v1.14.3-0.20260603163712-fb174e8925baReview222026-06-04
v1.14.3-0.20260602170352-7fc1fe66b9c1Review222026-06-03
v1.14.3-0.20260602150254-74e4738be230Review222026-06-03
v1.14.3-0.20260528202939-89ac856f8755Review222026-06-01
v0.0.0-20260528202939-89ac856f8755Review222026-06-01

Block this in CI

PkgRadar gates github.com/ava-labs/avalanchego/graft/evm (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/ava-labs/avalanchego/graft/[email protected]