PkgRadar

Go modules · proxy.golang.org

github.com/openmcp-project/mcp-operator

Go Mod Replace Local: go.mod replace directive redirects to a local filesystem path — non-portable / dev-time only.

Why PkgRadar flagged v0.56.1-0.20260619111302-d6d462e5eaae

SeveritySignalEvidence
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/openmcp-project/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.56.1-0.20260619111302-d6d462e5eaaeReview102026-06-20
v0.56.0Review102026-06-20

Block this in CI

PkgRadar gates github.com/openmcp-project/mcp-operator (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/openmcp-project/[email protected]
github.com/openmcp-project/mcp-operator — Go modules security scan | PkgRadar