PkgRadar

Go modules · proxy.golang.org

github.com/jmylchreest/colophon

Remote Payload, Credential file access

Why PkgRadar flagged v0.0.5-dev.1

SeveritySignalEvidence
mediumRemote Payloadgithub.com/jmylchreest/[email protected]/internal/publish/command/command.go
mediumRemote Payloadgithub.com/jmylchreest/[email protected]/internal/publish/git/git.go
mediumRemote Payloadgithub.com/jmylchreest/[email protected]/internal/publish/r2/r2.go
mediumRemote Payloadgithub.com/jmylchreest/[email protected]/internal/publish/s3/s3.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.5-dev.1Review342026-06-22
v0.0.4Review342026-06-22
v0.0.4-dev.2Review342026-06-22
v0.0.4-dev.1Review342026-06-22
v0.0.3-dev.2Review342026-06-22
v0.0.2-dev.4Review342026-06-22
v0.0.3Review342026-06-22
v0.0.2-dev.3Review342026-06-22
v0.0.2Review342026-06-22
v0.0.2-0.20260621002910-701dc362f147Review342026-06-22
v0.0.2-dev.1Review342026-06-22

Block this in CI

PkgRadar gates github.com/jmylchreest/colophon (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/jmylchreest/[email protected]