PkgRadar

Go modules · proxy.golang.org

github.com/ava-labs/avalanchego/graft/subnet-evm

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v1.14.3-0.20260609004932-345fdfaa749b

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/ava-labs/avalanchego/graft/[email protected]/plugin/evm/compile.go
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/ava-labs/avalanchego/graft/[email protected]/precompile/contracts/gaspricemanager/gaspricemanagertest/bindings/compile.go
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/ava-labs/avalanchego/graft/[email protected]/precompile/contracts/warp/warpbindings/compile.go
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/ava-labs/avalanchego/graft/[email protected]/precompile/contracts/warp/warptest/bindings/compile.go
mediumRemote Payloadmatched "curl " · github.com/ava-labs/avalanchego/graft/[email protected]/go.sum
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/ava-labs/avalanchego/graft/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.14.3-0.20260609004932-345fdfaa749bReview722026-06-10
v1.14.3-0.20260603151011-1339ef45dc6cReview622026-06-10
v1.14.3-0.20260602193739-919446e8501fReview622026-06-05
v1.14.3-0.20260603174913-47c06ddd6529Review722026-06-04
v1.14.3-0.20260603133342-15a574a27d75Review722026-06-04
v1.14.3-0.20260603163712-fb174e8925baReview722026-06-04
v1.14.3-0.20260602170352-7fc1fe66b9c1Review722026-06-03
v1.14.3-0.20260528202939-89ac856f8755Review722026-06-01
v0.0.0-20260528202939-89ac856f8755Review722026-06-01

Block this in CI

PkgRadar gates github.com/ava-labs/avalanchego/graft/subnet-evm (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/ava-labs/avalanchego/graft/[email protected]