PkgRadar

Go modules · proxy.golang.org

github.com/digitaldrywood/symphony

Remote Payload: matched "api.github.com/graphql"

Why PkgRadar flagged v0.5.0

SeveritySignalEvidence
mediumRemote Payloadmatched "api.github.com/graphql" · github.com/digitaldrywood/[email protected]/internal/config/config.go
mediumRemote Payloadmatched "api.github.com/graphql" · github.com/digitaldrywood/[email protected]/internal/connector/github/client.go
mediumRemote Payloadmatched "api.github.com/graphql" · github.com/digitaldrywood/[email protected]/internal/web/onboarding.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.5.0High risk362026-06-16
v0.4.0High risk362026-06-13
v0.3.0High risk362026-06-12
v0.2.0High risk362026-06-02
v0.1.2-0.20260531214627-064504111c0dHigh risk362026-06-01
v0.1.1High risk362026-06-01
v0.1.1-0.20260531165555-221936aecaf6High risk362026-06-01
v0.1.0High risk362026-06-01
v0.0.0-20260531161844-8dd1cfa64990High risk362026-06-01
v0.0.0-20260531155345-a256e52b7037High risk362026-06-01
v0.0.0-20260531152750-52baf6a05046High risk362026-06-01
v0.0.0-20260531145417-ba503d26e5ffHigh risk362026-06-01
v0.0.0-20260531143020-858a1512b8d4High risk362026-06-01
v0.0.0-20260531142209-ae9c65f4f2a7High risk362026-06-01
v0.0.0-20260531135526-2d2382b4d8d5High risk362026-06-01
v0.0.0-20260531134338-90e4fedd7086High risk362026-06-01
v0.0.0-20260531064529-9126a8fbc743High risk362026-06-01

Block this in CI

PkgRadar gates github.com/digitaldrywood/symphony (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/digitaldrywood/[email protected]