PkgRadar

Go modules · proxy.golang.org

github.com/foobarto/stado

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v0.75.0

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/foobarto/[email protected]/internal/plugins/bundled/embed.go
mediumRemote Payloadmatched "curl " · github.com/foobarto/[email protected]/cmd/stado/config_providers.go
mediumRemote Payloadmatched "github.com/BurntSushi/ripgrep/releases/download" · github.com/foobarto/[email protected]/hack/fetch-binaries.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.75.0Review492026-06-16
v0.74.0Review492026-06-15
v0.74.1Review492026-06-15
v0.71.0Review492026-06-15
v0.70.0Review492026-06-15
v0.69.0Review492026-06-15
v0.68.0Review492026-06-15
v0.67.0Review492026-06-14
v0.66.2Review492026-06-14
v0.66.1Review492026-06-14
v0.66.0Review492026-06-14
v0.65.0Review492026-06-14
v0.64.4-0.20260612213708-1f258112a8f9Review492026-06-13
v0.64.3Review492026-06-13
v0.64.2Review492026-06-13
v0.64.1Review492026-06-13
v0.63.1-0.20260612064431-89cbb850e231Review492026-06-13
v0.63.0Review492026-06-13
v0.61.1-0.20260610232603-3af75c4d8f09Review492026-06-11
v0.61.0Review492026-06-11
v0.60.3-0.20260610203334-b706c76b7f24Review492026-06-11
v0.60.2Review492026-06-11
v0.60.1Review492026-06-11
v0.60.0Review492026-06-11
v0.59.1Review492026-06-02
v0.59.0Review492026-06-02
v0.58.3-0.20260529145127-c5ada52f34a3Review492026-05-30
v0.58.2Review492026-05-30
v0.58.2-0.20260528215731-062c45bb620aReview492026-05-29
v0.57.1Review492026-05-29
v0.57.0Review492026-05-29

Block this in CI

PkgRadar gates github.com/foobarto/stado (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/foobarto/[email protected]