PkgRadar

Go modules · proxy.golang.org

github.com/gastownhall/gascity

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v1.1.1-0.20260613191253-e74147e451af

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/gastownhall/[email protected]/internal/api/huma_types.go
mediumRemote Payloadmatched "api.github.com/graphql" · github.com/gastownhall/[email protected]/internal/githubmonitor/client.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/gastownhall/[email protected]/internal/packregistry/config.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.1.1-0.20260613191253-e74147e451afReview442026-06-14
v1.1.1-0.20260608164101-67ce9d1e5c47Review442026-06-09
v1.1.1-0.20260603101741-a7d5a228f9fcReview442026-06-04
v1.1.1-0.20260601143605-801fa8919211Review442026-06-02
v1.1.1-0.20260530190243-cd7fd56869c0Review202026-05-31
v1.2.0-rc2Review202026-05-31
v1.1.1-0.20260529055231-a066a8f35e7aReview202026-05-30
v1.2.0Review202026-05-30
v1.2.0-rc1Review202026-05-29
v1.1.1-0.20260528173039-81df5a3ccf84Review202026-05-29

Block this in CI

PkgRadar gates github.com/gastownhall/gascity (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/gastownhall/[email protected]