PkgRadar

Go modules · proxy.golang.org

github.com/debops/debops

DNS / OAST exfiltration: matched "dig +short A \"${item_fqdn}\")\n $(dig +short AAAA \"${item_fqdn}\")\n $("

Why PkgRadar flagged v3.2.6+incompatible

SeveritySignalEvidence
highDNS / OAST exfiltrationmatched "dig +short A \"${item_fqdn}\")\n $(dig +short AAAA \"${item_fqdn}\")\n $(" · github.com/debops/[email protected]+incompatible/ansible/roles/rsnapshot/tasks/main.yml

Scanned versions

VersionVerdictScoreScanned (UTC)
v3.2.6+incompatibleHigh risk782026-06-10
v3.2.4+incompatibleHigh risk782026-06-10
v3.2.3+incompatibleHigh risk782026-06-10
v3.2.0+incompatibleHigh risk782026-06-10
v3.2.5+incompatibleHigh risk782026-06-10
v3.2.1+incompatibleHigh risk782026-06-10
v3.2.2+incompatibleHigh risk782026-06-10
v3.1.5+incompatibleHigh risk782026-06-10
v3.1.2+incompatibleHigh risk782026-06-10
v3.1.3+incompatibleHigh risk782026-06-10
v3.1.4+incompatibleHigh risk782026-06-10
v3.1.0+incompatibleHigh risk782026-06-10
v3.0.11+incompatibleHigh risk802026-06-10
v3.0.12+incompatibleHigh risk802026-06-10
v3.0.10+incompatibleHigh risk802026-06-10
v3.0.9+incompatibleHigh risk802026-06-10
v3.0.5+incompatibleHigh risk802026-06-10
v3.0.6+incompatibleHigh risk802026-06-10
v2.3.9+incompatibleHigh risk782026-06-10
v2.3.10+incompatibleHigh risk782026-06-10
v2.3.8+incompatibleHigh risk782026-06-10
v2.2.11+incompatibleHigh risk752026-06-10
v2.2.12+incompatibleHigh risk752026-06-10
v2.2.10+incompatibleHigh risk752026-06-10

Block this in CI

PkgRadar gates github.com/debops/debops (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/debops/[email protected]+incompatible