PkgRadar

Go modules · proxy.golang.org

github.com/odvcencio/gotreesitter

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged v0.20.3-0.20260606080756-4fd99449bc7a

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/odvcencio/[email protected]/cmd/gen_linguist/main.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.20.3-0.20260606080756-4fd99449bc7aReview152026-06-07
v0.20.3-0.20260606054116-0f7b1dc2e272Review152026-06-07
v0.20.3-0.20260606061236-fe0f98993eedReview152026-06-07
v0.20.0-rc4Review152026-06-05
v0.20.1Review152026-06-05
v0.20.0Review152026-06-03
v0.20.0-rc3Review152026-05-31
v0.20.0-rc2.0.20260529194451-f42a68be4f9fReview152026-05-30
v0.20.0-rc2Review152026-05-30
v0.20.0-rc2.0.20260528225640-c33966cb4594Review152026-05-30
v0.20.0-rc2.0.20260528222341-03fd3f7251f6Review152026-05-30

Block this in CI

PkgRadar gates github.com/odvcencio/gotreesitter (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/odvcencio/[email protected]