PkgRadar

Go modules · proxy.golang.org

github.com/jordanhubbard/arbiter

Shell Credential File Read, Remote Payload, Credential file access

Why PkgRadar flagged v0.1.18

SeveritySignalEvidence
highShell Credential File Read
mediumRemote Payload
mediumRemote Payload
mediumRemote Payload

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.1.18High risk802026-06-27
v0.1.21High risk802026-06-27
v0.1.19High risk802026-06-27
v0.1.16High risk802026-06-27
v0.1.5High risk772026-06-27
v0.1.14High risk802026-06-27
v0.1.23High risk802026-06-27
v0.1.8High risk802026-06-27
v0.1.11High risk802026-06-27
v0.1.22High risk802026-06-27
v0.1.15High risk802026-06-27
v0.1.24High risk802026-06-27
v0.1.13High risk802026-06-27
v0.1.6High risk802026-06-27
v0.1.7High risk802026-06-27
v0.1.9High risk802026-06-27
v0.1.17High risk802026-06-27
v0.1.3High risk772026-06-27
v0.1.12High risk802026-06-27
v0.1.4High risk772026-06-27
v0.1.10High risk802026-06-27
v0.0.1High risk582026-06-27
v0.1.20High risk802026-06-27
v0.1.25High risk802026-06-27
v0.1.27-0.20260421221956-cf9702bb49dfHigh risk802026-06-27
v0.1.26High risk802026-06-27

Block this in CI

PkgRadar gates github.com/jordanhubbard/arbiter (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/jordanhubbard/[email protected]
github.com/jordanhubbard/arbiter — Go modules security scan | PkgRadar