PkgRadar

Go modules · proxy.golang.org

github.com/castai/kimchi-cli

Remote Payload: matched "github.com/castai/kimchi/releases/download"

Why PkgRadar flagged v0.1.24

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/castai/kimchi/releases/download" · github.com/castai/[email protected]/internal/update/github_client.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.1.24Review122026-06-13
v0.1.36Low risk02026-06-13
v0.1.22Review122026-06-13
v0.1.2Review122026-06-13
v0.1.11Review122026-06-13
v0.1.30Review122026-06-13
v0.1.8Review122026-06-13
v0.1.23Review122026-06-13
v0.1.47Low risk02026-06-13
v0.1.14Review122026-06-13
v0.1.29Review122026-06-13
v0.1.32Review122026-06-13
v0.1.0Review122026-06-13
v0.1.45Low risk02026-06-13
v0.1.50Low risk02026-06-13
v0.1.43Low risk02026-06-13
v0.1.5Review122026-06-13
v0.1.35Low risk02026-06-13
v0.1.1Review122026-06-13
v0.1.25Review122026-06-13
v0.1.27Review122026-06-13
v0.1.40Low risk02026-06-13
v0.1.16Review122026-06-13
v0.1.28Review122026-06-13
v0.1.19Review122026-06-13
v0.1.21Review122026-06-13
v0.1.18Review122026-06-13
v0.1.26Review122026-06-13
v0.1.34Low risk02026-06-13
v0.1.48Low risk02026-06-13
v0.1.55-0.20260515111638-0b59e7b03c63Low risk02026-06-13

Block this in CI

PkgRadar gates github.com/castai/kimchi-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/castai/[email protected]