PkgRadar

Go modules · proxy.golang.org

github.com/google/Go-github

Remote Payload: matched "cURL "

Why PkgRadar flagged v2.0.0+incompatible

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/google/[email protected]+incompatible/github/activity.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v2.0.0+incompatibleReview122026-06-01
v16.0.0+incompatibleReview122026-06-01
v6.0.0+incompatibleReview122026-06-01
v13.0.0+incompatibleReview122026-06-01
v5.0.0+incompatibleReview122026-06-01
v14.0.0+incompatibleReview122026-06-01
v3.0.0+incompatibleReview122026-06-01
v15.0.0+incompatibleReview122026-06-01
v10.0.0+incompatibleReview122026-06-01
v12.0.0+incompatibleReview122026-06-01
v8.0.0+incompatibleReview122026-06-01
v7.0.0+incompatibleReview122026-06-01
v9.0.0+incompatibleReview122026-06-01
v11.0.0+incompatibleReview122026-06-01
v4.0.0+incompatibleReview122026-06-01
v17.0.0+incompatibleReview122026-06-01

Block this in CI

PkgRadar gates github.com/google/Go-github (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/google/[email protected]+incompatible