PkgRadar

Go modules · proxy.golang.org

github.com/devlikebear/tars

Remote Payload: matched "github.com/%s/releases/download"

Why PkgRadar flagged v0.34.2

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/%s/releases/download" · github.com/devlikebear/[email protected]/internal/release/release.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/devlikebear/[email protected]/internal/skillhub/registry.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/devlikebear/[email protected]/internal/skillhub/sources/anthropic/source.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/devlikebear/[email protected]/internal/skillhub/sources/hermes/source.go
mediumRemote Payloadmatched "curl " · github.com/devlikebear/[email protected]/internal/tool/prompt_validation.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.34.2High risk602026-06-10
v0.34.1High risk602026-06-08
v0.34.0High risk602026-06-08
v0.33.4High risk602026-06-03
v0.33.2High risk602026-06-03
v0.33.0High risk602026-05-31

Block this in CI

PkgRadar gates github.com/devlikebear/tars (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/devlikebear/[email protected]