PkgRadar

Go modules · proxy.golang.org

github.com/edgelesssys/contrast/imagepuller

Go Mod Replace Local: go.mod replace directive redirects to a local filesystem path — non-portable / dev-time only.

Why PkgRadar flagged v0.0.0-20260615125729-3c61e1a1282d

SeveritySignalEvidence
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/edgelesssys/contrast/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260615125729-3c61e1a1282dReview102026-06-16
v0.0.0-20260615110632-35f2a5b2be94Review102026-06-16
v0.0.0-20260615051213-7b53c2d612f7Review102026-06-16
v0.0.0-20260611154931-6615d9a567c3Review102026-06-12
v0.0.0-20260611093246-03f74709dd2bReview102026-06-12
v0.0.0-20260608095915-cc3d34b1a2e7Review102026-06-09
v0.0.0-20260608045208-0a13b4540c42Review102026-06-09
v0.0.0-20260603120623-406094d88986Review102026-06-04
v0.0.0-20260602120004-f99be92aa64fReview102026-06-03
v0.0.0-20260601115743-ca66f807b480Review102026-06-02
v0.0.0-20260601053317-c41978592d70Review102026-06-02
v0.0.0-20260529072545-959ddb9a345cReview102026-05-30
v0.0.0-20260528135839-006ce363736dReview102026-05-29

Block this in CI

PkgRadar gates github.com/edgelesssys/contrast/imagepuller (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/edgelesssys/contrast/[email protected]