PkgRadar

Go modules · proxy.golang.org

github.com/guigui-gui/guigui

Remote Payload: matched "github.com/notofonts/noto-cjk/releases/download"

Why PkgRadar flagged v0.0.0-20260609164110-721b8fc73a67

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/notofonts/noto-cjk/releases/download" · github.com/guigui-gui/[email protected]/basicwidget/cjkfont/gen.go
mediumRemote Payloadmatched "github.com/rsms/inter/releases/download" · github.com/guigui-gui/[email protected]/basicwidget/internal/font/gen.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260609164110-721b8fc73a67Review242026-06-10
v0.0.0-20260609132754-6657a6b63a4bReview242026-06-10
v0.0.0-20260608184217-54043e1fd5c7Review242026-06-09
v0.0.0-20260608152802-f45dc4965ab5Review242026-06-09
v0.0.0-20260608082839-24329a81d884Review242026-06-09
v0.0.0-20260607115543-7dec54853f72Review242026-06-08
v0.0.0-20260607101058-4461838550a1Review242026-06-08
v0.0.0-20260607093411-14d0182cfd45Review242026-06-08
v0.0.0-20260607091820-76c41f91d74bReview242026-06-08
v0.0.0-20260607084421-284e3efd9a91Review242026-06-08
v0.0.0-20260131180455-f22bdbf6f432Review242026-06-08
v0.0.0-20260606103249-bd5fcc7ba67aReview242026-06-07
v0.0.0-20260606101644-7a1a8785c740Review242026-06-07
v0.0.0-20260606011911-f79386c88588Review242026-06-07
v0.0.0-20260606005614-50e3a2115fc9Review242026-06-07
v0.0.0-20260605151512-64b24e581d57Review242026-06-06
v0.0.0-20260604152825-da84e5173b09Review242026-06-05
v0.0.0-20260529164304-f6fa4eb0c666Review242026-05-30
v0.0.0-20260529030226-3dfaa76ecefbReview242026-05-30
v0.0.0-20260528115658-b98466002991Review242026-05-29
v0.0.0-20260528045024-804a138becccReview242026-05-29

Block this in CI

PkgRadar gates github.com/guigui-gui/guigui (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/guigui-gui/[email protected]