PkgRadar

Go modules · proxy.golang.org

github.com/hrygo/hotplex-worker

Remote Payload: matched "cURL "

Why PkgRadar flagged v1.28.0

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/hrygo/[email protected]/internal/messaging/slack/converter.go
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/hrygo/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.28.0Review272026-06-13
v1.27.1-0.20260611221206-dfabe3e55cd6Review272026-06-13
v1.27.0Review272026-06-13
v1.26.0Review272026-06-10
v1.26.2Review272026-06-10
v1.26.3Review272026-06-10
v1.23.0Review272026-06-05
v1.24.2Review272026-06-05
v1.24.0Review272026-06-05
v1.23.2Review272026-06-05
v1.24.5-0.20260604090550-7288593dc7a6Review272026-06-05
v1.23.1Review272026-06-02
v1.21.1-0.20260530064122-6f5bf39e4c9eReview272026-05-31

Block this in CI

PkgRadar gates github.com/hrygo/hotplex-worker (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/hrygo/[email protected]