Go modules · proxy.golang.org
github.com/filecoin-project/go-lotus
Shell Credential File Read, Go Mod Replace Local
Why PkgRadar flagged v1.28.2-0.20260624034659-14730b091afb
| Severity | Signal | Evidence |
|---|---|---|
| high | Shell Credential File Read | github.com/filecoin-project/[email protected]/chain/types/keystore.go |
| high | Shell Credential File Read | github.com/filecoin-project/[email protected]/chain/wallet/memkeystore.go |
| medium | Go Mod Replace Local | github.com/filecoin-project/[email protected]/go.mod |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v1.28.2-0.20260624034659-14730b091afb | High risk | 100 | 2026-06-25 |
v1.36.1-rc1 | High risk | 100 | 2026-06-25 |
Block this in CI
pkgradar gate --ecosystem go github.com/filecoin-project/[email protected]