PkgRadar

Go modules · proxy.golang.org

github.com/cidverse/go-vcsapp

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged v0.0.0-20260611225349-494466d3bd8a

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/cidverse/[email protected]/pkg/platform/githubapp/githubapp.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/cidverse/[email protected]/pkg/platform/githubuser/convert.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260611225349-494466d3bd8aReview242026-06-13
v0.0.0-20260611163642-bb8f17571b28Review242026-06-12
v0.0.0-20260609185220-80ade47d83e6Review242026-06-10
v0.0.0-20260529145719-f9f7a9ad977bReview242026-05-30
v0.0.0-20260528213632-fb2283ff0ed2Review242026-05-29

Block this in CI

PkgRadar gates github.com/cidverse/go-vcsapp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/cidverse/[email protected]