PkgRadar

Go modules · proxy.golang.org

github.com/evilmartians/Lefthook

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged v1.10.7

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/evilmartians/[email protected]/internal/lefthook/validate.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.6.20Low risk02026-06-08
v1.6.21Low risk02026-06-08
v1.6.6Low risk02026-06-08
v1.6.7Low risk02026-06-08
v1.10.7Review122026-06-08
v1.7.11Low risk02026-06-08
v1.7.14Low risk02026-06-08
v1.7.17Low risk02026-06-08
v1.11.4Review122026-06-08
v1.10.9Review122026-06-08
v1.9.0Low risk02026-06-08
v1.8.3Low risk02026-06-08
v1.10.5Review122026-06-08
v1.13.3Review122026-06-08
v1.7.6Low risk02026-06-08
v1.7.4Low risk02026-06-08
v1.5.5Low risk02026-06-08
v1.5.7Low risk02026-06-08
v1.6.0Low risk02026-06-08
v1.6.1Low risk02026-06-08
v1.6.10Low risk02026-06-08
v1.6.14Low risk02026-06-08
v1.11.14Review122026-06-08
v1.6.18Low risk02026-06-08
v1.9.3Low risk02026-06-08
v1.10.2Review122026-06-08
v1.11.1Review122026-06-08
v1.11.16Review122026-06-08
v1.11.7Review122026-06-08
v1.13.2Review122026-06-08
v1.6.16Low risk02026-06-08
v1.7.0Low risk02026-06-08
v1.10.11Review122026-06-08
v1.13.4Review122026-06-08
v1.12.3Review122026-06-08
v1.12.2Review122026-06-08
v1.13.6Low risk02026-06-08

Block this in CI

PkgRadar gates github.com/evilmartians/Lefthook (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/evilmartians/[email protected]