PkgRadar

Go modules · proxy.golang.org

github.com/jeduden/mdsmith

Remote Payload: matched "github.com/shinagawa-web/gomarklint/releases/download"

Why PkgRadar flagged v0.49.1-0.20260615063226-80f89c6cd42d

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/shinagawa-web/gomarklint/releases/download" · github.com/jeduden/[email protected]/internal/release/bench.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/jeduden/[email protected]/internal/release/siteassets.go
mediumRemote Payloadmatched "github.com/jeduden/mdsmith/releases/download" · github.com/jeduden/[email protected]/internal/release/winmanifests.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.49.1-0.20260615063226-80f89c6cd42dHigh risk362026-06-16
v0.49.0-marketplaceHigh risk362026-06-16
v0.49.0High risk362026-06-16
v0.48.0High risk362026-06-15
v0.47.0High risk362026-06-15
v0.46.0High risk362026-06-13
v0.45.0High risk362026-06-13
v0.43.0High risk362026-06-13
v0.42.0High risk362026-06-12
v0.41.0High risk362026-06-12
v0.40.1-0.20260610192816-9095889709e2High risk462026-06-11
v0.39.0High risk462026-06-11
v0.40.0High risk462026-06-11
v0.38.1-0.20260608183554-b24561b258f5High risk462026-06-09
v0.0.0-20260608183554-b24561b258f5High risk462026-06-09
v0.37.0High risk462026-06-08
v0.38.0High risk462026-06-08
v0.36.1-0.20260606133125-bb85e7971603High risk462026-06-07
v0.33.0Review342026-06-07
v0.36.0High risk462026-06-07
v0.35.0High risk462026-06-07
v0.34.1-0.20260606005445-d47092244123High risk462026-06-07
v0.34.0Review342026-06-07
v0.32.1-0.20260604224639-4d8046192a82Review342026-06-06
v0.32.0Review342026-06-06
v0.31.1-0.20260602181907-095b17dc2e49Review342026-06-03
v0.31.0Review342026-06-03
v0.27.0Review342026-06-03
v0.30.0Review342026-06-03
v0.29.0Review342026-06-03
v0.25.1-0.20260527211846-db3a7057b472Review342026-05-30
v0.25.0Review342026-05-30
v0.24.0Review342026-05-30

Block this in CI

PkgRadar gates github.com/jeduden/mdsmith (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/jeduden/[email protected]