PkgRadar

Go modules · proxy.golang.org

github.com/modelcontextprotocol/go-sdk

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged v0.0.0-20250509192946-b7672185059b

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/modelcontextprotocol/[email protected]/mcp/protocol/generate.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.6.1-0.20260618135211-b85574f6851aLow risk02026-06-19
v0.0.0-20250509192946-b7672185059bReview122026-06-18
v1.6.1-0.20260616144253-d9728a88f3cdLow risk02026-06-17
v1.6.1-0.20260615074742-4dc99b48e1daLow risk02026-06-16
v1.6.1-0.20260608155210-dd978160abb3Low risk02026-06-09
v1.6.1-0.20260605101643-5045d86fb477Low risk02026-06-09
v1.6.1-0.20260602121701-c60a318d223cLow risk02026-06-05
v1.6.1-0.20260531083546-6d2bbff7d853Low risk02026-06-01
v1.6.1-0.20260529124634-dfb45f1e119eLow risk02026-05-31
v1.6.1-0.20260529072934-189a85ad92ffLow risk02026-05-30

Block this in CI

PkgRadar gates github.com/modelcontextprotocol/go-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/modelcontextprotocol/[email protected]