PkgRadar

Go modules · proxy.golang.org

github.com/external-secrets/external-secrets/generators/v1/sts

Go Mod Replace Local: go.mod replace directive redirects to a local filesystem path — non-portable / dev-time only.

Why PkgRadar flagged v0.0.0-20260615094606-ad8580d8bebe

SeveritySignalEvidence
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/external-secrets/external-secrets/generators/v1/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260615094606-ad8580d8bebeReview102026-06-17
v0.0.0-20260615082041-71048d540d4dReview102026-06-17
v0.0.0-20260615100817-a637233cd9cfReview102026-06-16
v0.0.0-20260615092647-94e564b59bd0Review102026-06-16
v0.0.0-20260610124725-6ed692570e7eReview102026-06-11
v0.0.0-20260609185905-8c9cbff118c0Review102026-06-10
v0.0.0-20260608204623-62d1adfd2036Review102026-06-09
v0.0.0-20260608131842-6c144f4bcfc4Review102026-06-09
v0.0.0-20260608081618-b42df25465d1Review102026-06-09
v0.0.0-20260608073834-94259afd105dReview102026-06-09
v0.0.0-20260607112204-e086e184753bReview102026-06-08
v0.0.0-20260607061953-4ba9dc81a757Review102026-06-08
v0.0.0-20260603083646-a38e5b08e076Review102026-06-04
v0.0.0-20260602090818-19d82f2ab129Review102026-06-03
v0.0.0-20260602012511-48d98c867526Review102026-06-03
v0.0.0-20260601094735-e1537972293fReview102026-06-02
v0.0.0-20260528125014-cedf209141b4Review102026-05-29

Block this in CI

PkgRadar gates github.com/external-secrets/external-secrets/generators/v1/sts (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/external-secrets/external-secrets/generators/v1/[email protected]