PkgRadar

Go modules · proxy.golang.org

github.com/knative/kn-plugin-func

Remote Payload: matched "github.com/kubernetes-sigs/kind/releases/download"

Why PkgRadar flagged v0.49.1-0.20260602011002-b8d4db53c088

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/kubernetes-sigs/kind/releases/download" · github.com/knative/[email protected]/pkg/cluster/binaries.go
mediumRemote Payloadmatched "github.com/knative/eventing/releases/download" · github.com/knative/[email protected]/pkg/cluster/eventing.go
mediumRemote Payloadmatched "github.com/kedacore/keda/releases/download" · github.com/knative/[email protected]/pkg/cluster/keda.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/knative/[email protected]/pkg/cluster/kubernetes.go
mediumRemote Payloadmatched "github.com/knative/serving/releases/download" · github.com/knative/[email protected]/pkg/cluster/serving.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/knative/[email protected]/pkg/cluster/tekton.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/knative/[email protected]/pkg/functions/function.go
mediumRemote Payloadmatched "cURL " · github.com/knative/[email protected]/pkg/pipelines/tekton/pipelines_provider.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.49.1-0.20260602011002-b8d4db53c088High risk1062026-06-04
v0.49.1Review342026-06-04

Block this in CI

PkgRadar gates github.com/knative/kn-plugin-func (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/knative/[email protected]