PkgRadar

Go modules · proxy.golang.org

github.com/go-openapi/spec

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v0.22.6

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/go-openapi/[email protected]/spec.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.22.6Review152026-06-15
v0.22.6-0.20260606074055-1ab4532d1096Review152026-06-08
v0.0.0-20260501103959-a5d0895d290cReview152026-06-08
v0.22.5-0.20260531081516-45b7fe19b6dcReview152026-06-01
v0.0.0-20180406015009-18bafbca2ddaReview152026-05-31
v0.0.0-20180326222602-f7d3cf6f35d4Review152026-05-31
v0.0.0-20180322214159-b1a574af1549Review152026-05-31
v0.0.0-20180302193043-fe19c0bc9082Review152026-05-31
v0.0.0-20180302193043-410b67ed1f1dReview152026-05-31
v0.0.0-20180213191501-b7cbfa8c8fa1Review152026-05-31
v0.0.0-20180213180752-7ede85316896Review152026-05-31
v0.0.0-20180209072353-ce2166cd8276Review152026-05-31
v0.0.0-20180207213947-c4e71bf47106Review152026-05-31
v0.22.5-0.20260529100141-971500643e42Review152026-05-30
v0.22.5-0.20260522093333-5c73b50fb446Review152026-05-30

Block this in CI

PkgRadar gates github.com/go-openapi/spec (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/go-openapi/[email protected]