PkgRadar

Go modules · proxy.golang.org

github.com/flipt-io/flipt/build

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged v0.0.0-20260605072153-2464918bebb0

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/flipt-io/flipt/[email protected]/testing/cli.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260609141007-550190482bc7Low risk02026-06-11
v0.0.0-20260605072153-2464918bebb0Review272026-06-06
v0.0.0-20260603214839-dba660d8baa2Low risk02026-06-06
v0.0.0-20260601173013-c7d6fb353c0aLow risk02026-06-03
v0.0.0-20260530103329-949f798c08efReview272026-06-01
v0.0.0-20260529153310-e93418bf9e75Low risk02026-06-01
v0.0.0-20260528061026-a130436ecc08Review272026-05-29
v0.0.0-20260528151805-5e89df6baeb3Low risk02026-05-29

Block this in CI

PkgRadar gates github.com/flipt-io/flipt/build (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/flipt-io/flipt/[email protected]