PkgRadar

Go modules · proxy.golang.org

github.com/mit-plv/fiat-crypto

Remote Payload: matched "wget "

Why PkgRadar flagged v0.1.7-0.20260527145144-368490bc4b02

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · github.com/mit-plv/[email protected]/etc/prepare-opam-release.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.1.7-0.20260528163142-901b3fb9243fLow risk02026-06-01
v0.0.0-20260528163142-901b3fb9243fLow risk02026-06-01
v0.1.7-0.20260527145144-368490bc4b02Review122026-05-29
v0.0.0-20260527145144-368490bc4b02Review122026-05-29

Block this in CI

PkgRadar gates github.com/mit-plv/fiat-crypto (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/mit-plv/[email protected]