PkgRadar

Go modules · proxy.golang.org

github.com/open-telemetry/opentelemetry-collector

Go Mod Replace Local: go.mod replace directive redirects to a local filesystem path — non-portable / dev-time only.

Why PkgRadar flagged v0.88.1-0.20231112151805-b570812b1e06

SeveritySignalEvidence
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/open-telemetry/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.154.1-0.20260612191519-af182d232650Low risk02026-06-15
v0.154.1-0.20260609210726-4d22af7a603dLow risk02026-06-11
v0.154.1-0.20260609121127-ac108050c2eaLow risk02026-06-10
v0.154.1-0.20260609115010-8e000d6e1125Low risk02026-06-10
v0.154.1-0.20260609100649-699932f50754Low risk02026-06-10
v0.154.0Low risk02026-06-10
v0.88.1-0.20231112151805-b570812b1e06Review102026-06-05
v0.0.0-20250402200755-cb5c3f4fb9dcLow risk02026-06-04
v0.122.2-0.20250327145723-ced2880d495cLow risk02026-06-04
v0.70.1-0.20230130215412-26bd7b2bf678Review102026-06-04
v0.153.1-0.20260602173553-a345b4e43d33Low risk02026-06-03
v0.153.1-0.20260602123538-2e0276ddc321Low risk02026-06-03
v0.153.1-0.20260602121533-92c3419ec258Low risk02026-06-03
v0.153.1-0.20260601213033-07f953b0f26fLow risk02026-06-03
v0.60.1-0.20220923151520-96e9af35c002Review102026-06-01
v0.92.1-0.20240118172122-8131d31601b8Review102026-05-30
v0.125.1-0.20250508034258-ac520a5c14ccLow risk02026-05-30
v0.153.1-0.20260528150546-fe2cf23ff222Low risk02026-05-30
v0.99.1-0.20240502202854-2875844e3c35Review102026-05-29
v0.96.1-0.20240306115632-b2693620eff6Review102026-05-29

Block this in CI

PkgRadar gates github.com/open-telemetry/opentelemetry-collector (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/open-telemetry/[email protected]