PkgRadar

Go modules · proxy.golang.org

github.com/mudler/localai

Remote Payload: matched "github.com/%s/%s/releases/download"

Why PkgRadar flagged v1.40.1-0.20260530221141-d5d8fe909d6d

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/%s/%s/releases/download" · github.com/mudler/[email protected]/cmd/launcher/internal/release_manager.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/mudler/[email protected]/core/config/gen_inference_defaults/main.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/mudler/[email protected]/pkg/downloader/uri.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/mudler/[email protected]/swagger/docs.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.40.1-0.20260530221141-d5d8fe909d6dHigh risk482026-05-31

Block this in CI

PkgRadar gates github.com/mudler/localai (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/mudler/[email protected]