PkgRadar

Go modules · proxy.golang.org

github.com/gardener/gardener-extension-os-suse-jeos

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v1.42.1-0.20260608140618-96956e5cc8c7

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/gardener/gardener-extension-os-suse-jeos@v1.42.1-0.20260608140618-96956e5cc8c7/charts/gardener-extension-os-suse-chost/doc.go
mediumRemote Payloadmatched "wget " · github.com/gardener/gardener-extension-os-suse-jeos@v1.42.1-0.20260608140618-96956e5cc8c7/pkg/controller/operatingsystemconfig/actuator.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.42.1-0.20260608140618-96956e5cc8c7Review272026-06-10
v1.42.0Review272026-06-10

Block this in CI

PkgRadar gates github.com/gardener/gardener-extension-os-suse-jeos (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/gardener/gardener-extension-os-suse-jeos@v1.42.1-0.20260608140618-96956e5cc8c7