PkgRadar

Go modules · proxy.golang.org

github.com/bluenviron/mediamtx

Remote Payload: matched "github.com/video-dev/hls.js/releases/download"

Why PkgRadar flagged v1.19.2-0.20260613094544-874b47d0b07b

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/video-dev/hls.js/releases/download" · github.com/bluenviron/[email protected]/internal/servers/hls/hlsjsdownloader/main.go
mediumRemote Payloadmatched "github.com/bluenviron/mediamtx-rpicamera/releases/download" · github.com/bluenviron/[email protected]/internal/staticsources/rpicamera/mtxrpicamdownloader/main.go
mediumRemote Payloadmatched "github.com/bluenviron/mediamtx/releases/download" · github.com/bluenviron/[email protected]/internal/upgrade/upgrade.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.0.1-0.20230813143823-659f19f8bbefReview122026-06-16
v1.19.2-0.20260613094544-874b47d0b07bHigh risk362026-06-14
v1.19.1-0.20260605150136-f5d7ed3138a5High risk362026-06-06
v1.18.3-0.20260531183348-0f5a76e253a7High risk362026-06-02
v0.0.0-20230807174413-bc8dcc4bb9d6Review122026-06-02
v0.23.9-0.20230807174413-bc8dcc4bb9d6Review122026-06-02
v1.18.3-0.20260529122720-e00c5516523cReview362026-05-30

Block this in CI

PkgRadar gates github.com/bluenviron/mediamtx (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/bluenviron/[email protected]