PkgRadar

Go modules · proxy.golang.org

github.com/i2p/i2p.i2p

Remote Payload: matched "wget "

Why PkgRadar flagged v0.0.0-20260527233336-d22f04b2d5c4

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · github.com/i2p/[email protected]/core/c/jbigi/download_gmp.sh
mediumRemote Payloadmatched "wget " · github.com/i2p/[email protected]/installer/lib/wrapper/copy.sh
mediumRemote Payloadmatched "wget " · github.com/i2p/[email protected]/installer/resources/makegeoip.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260612141457-aef56c9d9254Low risk02026-06-14
v0.0.0-20260607121140-eb8e417d9001Low risk02026-06-08
v0.0.0-20260530000007-c4b44795b1e6Low risk02026-06-01
v0.0.0-20260528160609-50954d5db40eLow risk02026-05-29
v0.0.0-20260527233336-d22f04b2d5c4Review362026-05-29

Block this in CI

PkgRadar gates github.com/i2p/i2p.i2p (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/i2p/[email protected]