PkgRadar

Go modules · proxy.golang.org

github.com/hajimehoshi/guigui

Remote Payload: matched "github.com/notofonts/noto-cjk/releases/download"

Why PkgRadar flagged v0.0.0-20260609164110-721b8fc73a67

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/notofonts/noto-cjk/releases/download" · github.com/hajimehoshi/[email protected]/basicwidget/cjkfont/gen.go
mediumRemote Payloadmatched "github.com/rsms/inter/releases/download" · github.com/hajimehoshi/[email protected]/basicwidget/internal/font/gen.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260609164110-721b8fc73a67Review242026-06-11
v0.0.0-20260606103249-bd5fcc7ba67aReview242026-06-07
v0.0.0-20260605151512-64b24e581d57Review242026-06-06
v0.0.0-20260604152825-da84e5173b09Review242026-06-05
v0.0.0-20260529164304-f6fa4eb0c666Review242026-06-02
v0.0.0-20260529030226-3dfaa76ecefbReview242026-05-30

Block this in CI

PkgRadar gates github.com/hajimehoshi/guigui (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/hajimehoshi/[email protected]