PkgRadar

Go modules · proxy.golang.org

github.com/encoredev/encore

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged v1.57.9-0.20260611132840-41c3ef0f5f23

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/encoredev/[email protected]/cli/cmd/encore/app/create_form.go
mediumRemote Payloadmatched "curl " · github.com/encoredev/[email protected]/cli/cmd/encore/check.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/encoredev/[email protected]/cli/cmd/encore/llm_rules/tool.go
mediumRemote Payloadmatched "cURL " · github.com/encoredev/[email protected]/cli/daemon/run/runtime_config2.go
mediumRemote Payloadmatched "curl " · github.com/encoredev/[email protected]/cli/daemon/run_spec.go
mediumRemote Payloadmatched "curl " · github.com/encoredev/[email protected]/cli/internal/update/update.go
mediumRemote Payloadmatched "cURL " · github.com/encoredev/[email protected]/v2/app/validate_objects.go
mediumRemote Payloadmatched "cURL " · github.com/encoredev/[email protected]/v2/parser/infra/objects/errors.go
mediumRemote Payloadmatched "cURL " · github.com/encoredev/[email protected]/v2/parser/infra/objects/usage.go
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/encoredev/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.57.9-0.20260611132840-41c3ef0f5f23High risk1102026-06-13
v0.0.0-20260611132840-41c3ef0f5f23High risk1102026-06-13
v0.0.0-20260610124723-c3e12f1cd544High risk1102026-06-12
v1.57.8High risk1102026-06-11
v0.0.0-20260609135530-343395095466High risk1102026-06-11
v0.0.0-20260602135951-0993633cb60cHigh risk1102026-06-05
v1.57.6High risk1102026-06-04
v1.57.6-0.20260529100630-a9c45a0215b5High risk1102026-05-31
v0.0.0-20260529100630-a9c45a0215b5High risk1102026-05-31
v1.57.6-0.20260527090329-ee405db81bb0High risk1102026-05-30
v0.0.0-20260527090329-ee405db81bb0High risk1102026-05-30

Block this in CI

PkgRadar gates github.com/encoredev/encore (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/encoredev/[email protected]