PkgRadar

Go modules · proxy.golang.org

github.com/celestiaorg/celestia-app/v9

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged v9.0.0-arabica.0.20260616141331-ff6456b44e4e

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/celestiaorg/celestia-app/[email protected]/cmd/celestia-appd/cmd/download_genesis.go
mediumRemote Payloadmatched "curl " · github.com/celestiaorg/celestia-app/[email protected]/tools/measure-tip-sync/main.go
mediumRemote Payloadmatched "curl " · github.com/celestiaorg/celestia-app/[email protected]/tools/talis/deployment.go
mediumRemote Payloadmatched "curl " · github.com/celestiaorg/celestia-app/[email protected]/tools/talis/genesis.go
mediumRemote Payloadmatched "curl " · github.com/celestiaorg/celestia-app/[email protected]/tools/talis/sync_node_cmd.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v9.0.0-arabica.0.20260616141331-ff6456b44e4eHigh risk702026-06-17
v9.0.4High risk702026-06-17
v9.0.4-mochaHigh risk702026-06-16
v9.0.0-arabica.0.20260613155441-4c9cee27af16High risk702026-06-15
v9.0.4-arabicaHigh risk702026-06-15
v9.0.0-arabica.0.20260605091622-a3d68db44642High risk702026-06-09
v9.0.2-arabicaHigh risk702026-06-05
v9.0.0-arabica.0.20260604095359-8dcb69b8091fHigh risk702026-06-05
v9.0.2-mochaHigh risk702026-06-05
v9.0.1-arabicaHigh risk702026-06-03
v9.0.0-arabica.0.20260602062536-12e70991e74cHigh risk702026-06-03
v9.0.1-mochaHigh risk702026-06-03
v9.0.0-arabica.0.20260601094728-4422f24c27b5High risk702026-06-02
v9.0.0-mochaHigh risk702026-06-02

Block this in CI

PkgRadar gates github.com/celestiaorg/celestia-app/v9 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/celestiaorg/celestia-app/[email protected]