PkgRadar

Go modules · proxy.golang.org

github.com/loft-sh/vcluster

Remote Payload: matched "github.com/loft-sh/kubernetes/releases/download"

Why PkgRadar flagged v0.35.0-rc.5

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/loft-sh/kubernetes/releases/download" · github.com/loft-sh/[email protected]/cmd/vcluster/cmd/node/upgrade.go
mediumRemote Payloadmatched "curl " · github.com/loft-sh/[email protected]/cmd/vclusterctl/cmd/token/create.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/loft-sh/[email protected]/e2e-next/setup/csi.go
mediumRemote Payloadmatched "curl " · github.com/loft-sh/[email protected]/e2e-next/test_core/coredns/test_coredns.go
mediumRemote Payloadmatched "curl " · github.com/loft-sh/[email protected]/pkg/cli/create_docker.go
mediumRemote Payloadmatched "cURL " · github.com/loft-sh/[email protected]/pkg/snapshot/s3/store.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.35.0-rc.5High risk772026-06-12
v0.34.3-rc.2High risk892026-06-11
v0.35.0-rc.3High risk772026-06-11
v0.34.2High risk892026-06-09
v0.35.0-rc.2.0.20260605174155-fc79f8be9eebHigh risk772026-06-06
v0.34.2-rc.2High risk892026-06-06
v0.34.2-rc.1.0.20260605190457-de49d3bdf9faHigh risk892026-06-06
v0.35.0-rc.2.0.20260605074107-5ab4f5e0665dHigh risk772026-06-06
v0.35.0-rc.2.0.20260604204746-6ffbc797eb13High risk772026-06-05
v0.34.2-rc.1High risk892026-06-05
v0.35.0-rc.2High risk772026-06-05
v0.35.0-rc.1High risk772026-06-05
v0.35.0-alpha.8.0.20260604165405-333bd5de3bd1High risk772026-06-05
v0.35.0-alpha.8.0.20260604100306-3031d19ca041High risk772026-06-05
v0.35.0-alpha.8Review772026-05-30
v0.33.3Review892026-05-30
v0.34.1Review892026-05-29
v0.35.0-alpha.7.0.20260528135051-4e14e16ca157Review772026-05-29

Block this in CI

PkgRadar gates github.com/loft-sh/vcluster (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/loft-sh/[email protected]