Remote Payload, Credential file access, Obfuscation Density
Why PkgRadar flagged v3.0.0-rc.3
Severity
Signal
medium
Remote Payload
Showing signal labels only. Sign in to view the exact matched indicators for each finding.
Scanned versions
Version
Verdict
Score
Scanned (UTC)
v3.0.0-rc.3
Review
17
2026-08-28
v3.0.0-rc.2
Review
11
2026-07-30
v3.0.0-rc.1
Low risk
0
2026-07-17
Verdict reflects the highest-severity signal, not just the additive score: a single high-severity finding outranks a higher score made up of lower-severity ones, so a lower-scored version can still carry the stronger verdict.
Block this in CI
PkgRadar gates github.com/boeing/config-file-validator/v3 (and every other dependency) before it merges. One line in your pipeline:
pkgradar gate --ecosystem go github.com/boeing/config-file-validator/[email protected]
Prefer zero config? Install the GitHub App and it gates every pull request automatically — no pipeline edits, no API key.