PkgRadar

Go modules · proxy.golang.org

github.com/discourse/dv

Credential file access: matched "AWS_ACCESS_KEY"

Why PkgRadar flagged v1.0.94-0.20260605073702-0841c83077d9

SeveritySignalEvidence
highCredential file accessmatched "AWS_ACCESS_KEY" · github.com/discourse/[email protected]/internal/ai/providers/bedrock.go
mediumRemote Payloadmatched "curl " · github.com/discourse/[email protected]/internal/assets/localproxy/main.go
mediumRemote Payloadmatched "curl " · github.com/discourse/[email protected]/internal/cli/new.go
mediumRemote Payloadmatched "curl " · github.com/discourse/[email protected]/internal/cli/update.go
mediumRemote Payloadmatched "github.com/%s/%s/releases/download" · github.com/discourse/[email protected]/internal/cli/upgrade.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.0.94-0.20260605073702-0841c83077d9High risk982026-06-07
v1.0.93High risk982026-06-07
v1.0.91High risk982026-06-05
v1.0.89High risk982026-06-05
v1.0.93-0.20260604143506-ac4cfb7e4885High risk982026-06-05
v1.0.92High risk982026-06-05
v1.0.91-0.20260601144147-e56cb4e3040eHigh risk982026-06-03
v1.0.90High risk982026-06-03
v1.0.88High risk1102026-05-31

Block this in CI

PkgRadar gates github.com/discourse/dv (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/discourse/[email protected]