PkgRadar

Go modules · proxy.golang.org

github.com/mvanhorn/printing-press-library/library/payments/lemonsqueezy

Webhook Exfil Endpoint: matched "ngrok-free.app"

Why PkgRadar flagged v0.0.0-20260611231308-ad6fcb11fb9b

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok-free.app" · github.com/mvanhorn/printing-press-library/library/payments/[email protected]/internal/cli/webhook_audit.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260611231308-ad6fcb11fb9bHigh risk402026-06-12
v0.0.0-20260611212419-e39a00627666High risk402026-06-12
v0.0.0-20260611041038-76d8000051b8High risk402026-06-12
v0.0.0-20260608235501-8c43a290b28cHigh risk402026-06-09
v0.0.0-20260608071213-6b8e2da7bdf8High risk402026-06-09
v0.0.0-20260608064329-63959b91e994High risk402026-06-09
v0.0.0-20260608060251-1a76b03c41dfHigh risk402026-06-09
v0.0.0-20260608042424-40610a4e649eHigh risk402026-06-09
v0.0.0-20260608034932-adba25a037caHigh risk402026-06-09
v0.0.0-20260608034340-6c9dba559fdeHigh risk402026-06-09
v0.0.0-20260608031648-a8f4a650f404High risk402026-06-09
v0.0.0-20260608031126-a87f0a1bf103High risk402026-06-09
v0.0.0-20260608003942-f17aec23ae73High risk402026-06-08
v0.0.0-20260607235417-920e8e73049dHigh risk402026-06-08
v0.0.0-20260606194244-db0612d8141cHigh risk402026-06-07
v0.0.0-20260606055902-f8f5f3cbc444High risk402026-06-07
v0.0.0-20260606043900-c3086c3f1de4High risk402026-06-07
v0.0.0-20260605215946-5ef29ab45ca6High risk402026-06-06
v0.0.0-20260605055427-38981b46abc0High risk402026-06-06
v0.0.0-20260604065235-ab7c0c7674edHigh risk402026-06-05
v0.0.0-20260604043326-d345fd364cbfHigh risk402026-06-05
v0.0.0-20260603063256-66ab31d8ca1fHigh risk402026-06-04
v0.0.0-20260601213552-f689a52c0d6fHigh risk402026-06-02
v0.0.0-20260601084814-4991a88d42cbHigh risk402026-06-02
v0.0.0-20260601072908-5beaabe9b0f5High risk402026-06-02
v0.0.0-20260601025923-c78f09b00c36High risk402026-06-02
v0.0.0-20260531072015-3e817cc1da10High risk402026-06-01
v0.0.0-20260531064857-dc13ebbd9434High risk402026-06-01
v0.0.0-20260531064004-2935442644d3High risk402026-06-01
v0.0.0-20260531063508-502d13b5e8faHigh risk402026-06-01
v0.0.0-20260530172710-54df1b8ab9f5High risk402026-05-31
v0.0.0-20260530085202-58b4b3fa9d30High risk402026-05-31
v0.0.0-20260530061554-6183c70f5562High risk402026-05-31
v0.0.0-20260529185117-3a94c4cc6e87High risk402026-05-30

Block this in CI

PkgRadar gates github.com/mvanhorn/printing-press-library/library/payments/lemonsqueezy (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/mvanhorn/printing-press-library/library/payments/[email protected]