PkgRadar

Go modules · proxy.golang.org

github.com/datadog/dd-trace-go/contrib/graph-gophers/graphql-go/v2

Go Mod Replace Local: go.mod replace directive redirects to a local filesystem path — non-portable / dev-time only.

Why PkgRadar flagged v2.9.0-dev.0.20260527180125-5e9edeb0c504

SeveritySignalEvidence
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/datadog/dd-trace-go/contrib/graph-gophers/graphql-go/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v2.8.3-rc.1Low risk02026-06-04
v2.7.0-dev.1.0.20260318145258-75241b000f75Low risk02026-06-04
v2.9.0-dev.0.20260603142526-9d73480f12ceLow risk02026-06-04
v2.7.0-dev.1.0.20260313104931-0957c7c63dfeLow risk02026-06-04
v2.9.0-dev.0.20260529131851-560307d67362Low risk02026-05-30
v2.7.0-dev.1.0.20260319202948-6f4b819ebee6Low risk02026-05-30
v2.9.0-dev.0.20260528184834-a37e8b7816e2Low risk02026-05-30
v2.7.0-dev.1.0.20260312161155-1ebb74bfed5bLow risk02026-05-30
v2.9.0-dev.0.20260527180125-5e9edeb0c504Review102026-05-29

Block this in CI

PkgRadar gates github.com/datadog/dd-trace-go/contrib/graph-gophers/graphql-go/v2 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/datadog/dd-trace-go/contrib/graph-gophers/graphql-go/[email protected]