PkgRadar

Go modules · proxy.golang.org

github.com/gke-labs/gemini-for-kubernetes-development/factory

Remote Payload: matched "github.com/kubernetes-sigs/agent-sandbox/releases/download"

Why PkgRadar flagged v0.0.0-20260611205734-ffc151d94bfd

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/kubernetes-sigs/agent-sandbox/releases/download" · github.com/gke-labs/gemini-for-kubernetes-development/[email protected]/pkg/commands/up.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260611205734-ffc151d94bfdReview122026-06-12
v0.0.0-20260610062841-7e14030c3af4Review122026-06-11
v0.0.0-20260608175935-ad8311dda8f1Review122026-06-09
v0.0.0-20260604081217-c5407ad4fb53Review122026-06-05
v0.0.0-20260602223235-d7891ad6ec83Review122026-06-04
v0.0.0-20260529233059-91e877831e40Review122026-06-02

Block this in CI

PkgRadar gates github.com/gke-labs/gemini-for-kubernetes-development/factory (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/gke-labs/gemini-for-kubernetes-development/[email protected]