Go modules · proxy.golang.org
github.com/esm-dev/esm.sh
Remote Payload: matched "github.com/denoland/deno/releases/download"
Why PkgRadar flagged v0.0.0-20260607061920-6debc6efa24b
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "github.com/denoland/deno/releases/download" · github.com/esm-dev/[email protected]/internal/deno/deno.go |
| medium | Remote Payload | matched "github.com/esm-dev/cjs-module-lexer/releases/download" · github.com/esm-dev/[email protected]/server/cjs_module_lexer.go |
| medium | Remote Payload | matched "raw.githubusercontent.com" · github.com/esm-dev/[email protected]/server/router.go |
| medium | Credential file access | matched ".npmrc" · github.com/esm-dev/[email protected]/server/build_analyzer.go |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v0.0.0-20260607061920-6debc6efa24b | High risk | 61 | 2026-06-08 |
v0.0.0-20260607023924-b3aa35ef26cf | High risk | 61 | 2026-06-08 |
Block this in CI
pkgradar gate --ecosystem go github.com/esm-dev/[email protected]