Go modules · proxy.golang.org
github.com/bufbuild/plugins
Remote Payload: matched "github.com/%s/%s/releases/download"
Why PkgRadar flagged v0.0.0-20260615151425-b059dc166591
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "github.com/%s/%s/releases/download" · github.com/bufbuild/[email protected]/internal/cmd/release/main.go |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v0.0.0-20260615151425-b059dc166591 | Review | 12 | 2026-06-16 |
v0.0.0-20260614003632-019b47455f5c | Review | 12 | 2026-06-15 |
v0.0.0-20260611232854-71ba86ce7e08 | Review | 12 | 2026-06-13 |
v0.0.0-20260609225515-14c91c78d276 | Review | 12 | 2026-06-10 |
v0.0.0-20260609131010-f3fcbaee4427 | Review | 12 | 2026-06-10 |
v0.0.0-20260604162751-feb271862be9 | Review | 12 | 2026-06-05 |
v0.0.0-20260603165306-ca0928b3f798 | Review | 12 | 2026-06-04 |
v0.0.0-20260601215903-bd576a2b17e4 | Review | 12 | 2026-06-02 |
v0.0.0-20260601150801-336971389262 | Review | 12 | 2026-06-02 |
v0.0.0-20260529152901-b5cfeebcdf07 | Review | 12 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem go github.com/bufbuild/[email protected]