PkgRadar

Go modules · proxy.golang.org

github.com/compartmentdev/compartment

Remote Payload: matched "github.com/${release_repository}/releases/download"

Why PkgRadar flagged v0.0.0-20260528062942-3937ba884e82

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/${release_repository}/releases/download" · github.com/compartmentdev/[email protected]/install.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.9.1Low risk02026-06-05
v0.0.0-20260604164154-591aaebe9405Low risk02026-06-05
v0.0.0-20260604144930-9613b193d4b4Low risk02026-06-05
v0.9.0Low risk02026-06-05
v0.0.0-20260604132942-dd357d1f209cLow risk02026-06-05
v0.0.0-20260604094949-b18fa3fbe941Low risk02026-06-05
v0.0.0-20260603093715-b55a391ce81cLow risk02026-06-04
v0.8.0Low risk02026-06-04
v0.0.0-20260603083555-f8028338bc08Low risk02026-06-04
v0.0.0-20260603081906-28ac5ef5a3ecLow risk02026-06-04
v0.0.0-20260602164129-7fdde0245d01Low risk02026-06-03
v0.0.0-20260528141148-2eb1b3646804Low risk02026-05-29
v0.0.0-20260528124426-3026cda70fe3Low risk02026-05-29
v0.0.0-20260528062942-3937ba884e82Review122026-05-29

Block this in CI

PkgRadar gates github.com/compartmentdev/compartment (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/compartmentdev/[email protected]