PkgRadar

Go modules · proxy.golang.org

github.com/nvidia/bare-metal-manager-rest

Go Mod Replace Local: go.mod replace directive redirects to a local filesystem path — non-portable / dev-time only.

Why PkgRadar flagged v0.0.0-20260601193432-d3a07c6f3b9c

SeveritySignalEvidence
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/nvidia/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260601193432-d3a07c6f3b9cReview102026-06-04
v0.0.0-20260529203725-19adec2708f9Review102026-05-30
v1.6.1-0.20260529192043-59a3ae88191bReview102026-05-30
v1.6.1-0.20260527234750-10d31872a3cfReview102026-05-30
v0.0.0-20260527234750-10d31872a3cfReview102026-05-30
v1.6.1-0.20260528231947-ef1b731f68bcReview102026-05-30
v0.0.0-20260528231947-ef1b731f68bcReview102026-05-30
v1.6.1-0.20260528173234-c39c263624a9Review102026-05-29

Block this in CI

PkgRadar gates github.com/nvidia/bare-metal-manager-rest (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/nvidia/[email protected]
github.com/nvidia/bare-metal-manager-rest — Go modules security scan | PkgRadar