PkgRadar

Go modules · proxy.golang.org

github.com/defanglabs/pulumi-defang

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged v1.0.1-0.20260602151546-5ac2986b13de

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/defanglabs/[email protected]/provider/defangaws/provider.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/defanglabs/[email protected]/provider/defangazure/provider.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/defanglabs/[email protected]/provider/defanggcp/provider.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.0.1-0.20260602151546-5ac2986b13deHigh risk412026-06-04
v0.0.0-20260602151546-5ac2986b13deHigh risk412026-06-04

Block this in CI

PkgRadar gates github.com/defanglabs/pulumi-defang (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/defanglabs/[email protected]