PkgRadar

Go modules · proxy.golang.org

github.com/molior-dbs/aptly

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v1.6.2-molior6

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/molior-dbs/[email protected]/main.go
mediumRemote Payloadmatched "wget " · github.com/molior-dbs/[email protected]/pgp/gnupg.go
mediumRemote Payloadmatched "wget " · github.com/molior-dbs/[email protected]/pgp/internal.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.6.2-molior6Review392026-06-15
v1.6.2-molior7Review392026-06-15
v1.6.2-molior8Review392026-06-15
v1.6.2-molior4Review392026-06-15
v1.6.2-molior5Review392026-06-15
v1.6.2-molior9Review392026-06-15
v1.6.2-molior2Review392026-06-15
v1.6.2-molior3Review392026-06-15
v1.6.2-molior1Review392026-06-15

Block this in CI

PkgRadar gates github.com/molior-dbs/aptly (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/molior-dbs/[email protected]