PkgRadar

Go modules · proxy.golang.org

github.com/laurentsimon/slsa-github-generator

Remote Payload

Why PkgRadar flagged v0.0.7

SeveritySignalEvidence
mediumRemote Payloadgithub.com/laurentsimon/[email protected]/go.sum

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20240321100139-c747fe7769adLow risk02026-06-25
v1.10.0-rc.0Low risk02026-06-25
v0.0.7Review122026-06-25
v0.0.6Review122026-06-25
v0.0.17Review122026-06-25
v1.1.0Review242026-06-25
v0.0.22Review122026-06-25
v0.0.18Review122026-06-25
v1.9.0-rc.0Low risk02026-06-25
v0.0.19Review122026-06-25
v0.0.9Review122026-06-25
v0.0.21Review122026-06-25
v0.0.15Review122026-06-25
v1.2.0Review242026-06-25
v0.0.13Review122026-06-25
v0.0.2Review122026-06-25
v0.0.14Review122026-06-25
v0.0.16Review122026-06-25
v0.0.4Review122026-06-25
v0.0.12Review122026-06-25
v0.0.3Review122026-06-25
v0.0.10Review122026-06-25
v0.0.5Review122026-06-25
v1.1.1Review242026-06-25
v0.0.1Review122026-06-25
v1.0.0Review242026-06-25
v0.0.20Review122026-06-25
v1.10.0Low risk02026-06-25
v0.0.11Review122026-06-25
v1.10.1-0.20240422213022-472fb17d7c6dLow risk02026-06-25

Block this in CI

PkgRadar gates github.com/laurentsimon/slsa-github-generator (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/laurentsimon/[email protected]