PkgRadar

Go modules · proxy.golang.org

github.com/google/osv.dev/go

Go Mod Replace Local: go.mod replace directive redirects to a local filesystem path — non-portable / dev-time only.

Why PkgRadar flagged v0.0.0-20260616011302-dd08243aaacd

SeveritySignalEvidence
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/google/osv.dev/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260616011302-dd08243aaacdReview152026-06-17
v0.0.0-20260615032909-f6cace023093Review152026-06-16
v0.0.0-20260611021350-93af580d6643Review152026-06-12
v0.0.0-20260610061249-c1834978d05dReview152026-06-11
v0.0.0-20260610053825-a778a0885586Review152026-06-11
v0.0.0-20260610030806-89a739907ff6Review152026-06-11
v0.0.0-20260610024337-dd6ad8a53b23Review152026-06-11
v0.0.0-20260610020225-268543577997Review152026-06-11
v0.0.0-20260610002906-dc5cc823b102Review152026-06-11
v0.0.0-20260609033917-8623f6c99355Review152026-06-10
v0.0.0-20260605040321-b617725d0791Review152026-06-07
v0.0.0-20260603000917-c77cf8241321Review152026-06-04
v0.0.0-20260602235835-22d70f0e5ae3Review152026-06-04
v0.0.0-20260602032617-95be4bba2dbfReview152026-06-03
v0.0.0-20260602011335-5705afe3d3c5Review152026-06-03
v0.0.0-20260601034002-37aa58a4f602Review152026-06-02
v0.0.0-20260601025831-f4bf0e41049fReview152026-06-02
v0.0.0-20260601005729-1fad7a8b2153Review152026-06-02
v0.0.0-20260529005747-128e9272ef9fReview152026-05-30
v0.0.0-20260528052143-310a971ddc18Review152026-05-29
v0.0.0-20260527235502-768a541c62b5Review272026-05-29

Block this in CI

PkgRadar gates github.com/google/osv.dev/go (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/google/osv.dev/[email protected]