PkgRadar

Go modules · proxy.golang.org

github.com/mvanhorn/printing-press-library/library/payments/revenuecat

Webhook Exfil Endpoint: matched "ngrok-free.app"

Why PkgRadar flagged v0.0.0-20260612080247-f1a2fa4c7007

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok-free.app" · github.com/mvanhorn/printing-press-library/library/payments/[email protected]/internal/cli/webhook_audit.go
mediumRemote Payloadmatched "cUrl " · github.com/mvanhorn/printing-press-library/library/payments/[email protected]/internal/types/types.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260612080247-f1a2fa4c7007High risk522026-06-13
v0.0.0-20260612051203-0e7f6cb217f6High risk522026-06-13
v0.0.0-20260611231308-ad6fcb11fb9bHigh risk522026-06-12
v0.0.0-20260611041038-76d8000051b8High risk522026-06-12
v0.0.0-20260610030024-8b580537a9a4High risk522026-06-11
v0.0.0-20260608071333-e4b890462dafHigh risk522026-06-09
v0.0.0-20260608064329-63959b91e994High risk522026-06-09
v0.0.0-20260608060251-1a76b03c41dfHigh risk522026-06-09
v0.0.0-20260608042424-40610a4e649eHigh risk522026-06-09
v0.0.0-20260608034932-adba25a037caHigh risk522026-06-09
v0.0.0-20260608034340-6c9dba559fdeHigh risk522026-06-09
v0.0.0-20260608031648-a8f4a650f404High risk522026-06-09
v0.0.0-20260608031126-a87f0a1bf103High risk522026-06-09
v0.0.0-20260608003942-f17aec23ae73High risk522026-06-08
v0.0.0-20260607235417-920e8e73049dHigh risk522026-06-08
v0.0.0-20260607043004-7c024eb5ed09High risk522026-06-08
v0.0.0-20260606194244-db0612d8141cHigh risk522026-06-07
v0.0.0-20260606053903-875fce8db3cbHigh risk522026-06-07
v0.0.0-20260605215946-5ef29ab45ca6High risk522026-06-06
v0.0.0-20260605055427-38981b46abc0High risk522026-06-06
v0.0.0-20260604065235-ab7c0c7674edHigh risk522026-06-05
v0.0.0-20260604043326-d345fd364cbfHigh risk522026-06-05
v0.0.0-20260603221945-92ae6a539159High risk522026-06-04
v0.0.0-20260603203410-d58ef32867aeHigh risk522026-06-04
v0.0.0-20260603063256-66ab31d8ca1fHigh risk522026-06-04
v0.0.0-20260601213552-f689a52c0d6fHigh risk522026-06-02
v0.0.0-20260601192823-fda1c66cc164High risk522026-06-02
v0.0.0-20260601084814-4991a88d42cbHigh risk522026-06-02
v0.0.0-20260601072908-5beaabe9b0f5High risk522026-06-02
v0.0.0-20260601025923-c78f09b00c36High risk522026-06-02
v0.0.0-20260531072015-3e817cc1da10High risk522026-06-01
v0.0.0-20260531064857-dc13ebbd9434High risk522026-06-01
v0.0.0-20260531063508-502d13b5e8faHigh risk522026-06-01
v0.0.0-20260530172710-54df1b8ab9f5High risk522026-05-31
v0.0.0-20260530064435-26006796d424High risk522026-05-31
v0.0.0-20260530061554-6183c70f5562High risk522026-05-31
v0.0.0-20260530031521-8871fb8094a6High risk522026-05-31
v0.0.0-20260530031153-cb2a99b0f08dHigh risk522026-05-31

Block this in CI

PkgRadar gates github.com/mvanhorn/printing-press-library/library/payments/revenuecat (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/mvanhorn/printing-press-library/library/payments/[email protected]