Go modules · proxy.golang.org
github.com/juanfont/atalaia
Shipped Live Secret
Why PkgRadar flagged v0.5.5-0.20260621204205-815ca61c7e40
| Severity | Signal | Evidence |
|---|---|---|
| high | Shipped Live Secret | github.com/juanfont/[email protected]/internal/llm/shortcircuit.go |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v0.5.5-0.20260621204205-815ca61c7e40 | High risk | 45 | 2026-06-24 |
v0.5.3 | High risk | 45 | 2026-06-24 |
v0.5.2 | High risk | 45 | 2026-06-24 |
v0.5.4 | High risk | 45 | 2026-06-24 |
v0.5.1 | Low risk | 0 | 2026-06-19 |
v0.4.1 | Low risk | 0 | 2026-06-19 |
v0.4.0 | Low risk | 0 | 2026-06-19 |
v0.3.0 | Low risk | 0 | 2026-06-19 |
v0.5.0 | Low risk | 0 | 2026-06-19 |
Block this in CI
pkgradar gate --ecosystem go github.com/juanfont/[email protected]