PkgRadar

Go modules · proxy.golang.org

github.com/pipe-cd/pipecd

Remote Payload: matched "github.com/pipe-cd/pipecd/releases/download"

Why PkgRadar flagged v0.56.1-0.20260607075416-dcc037e06c3b

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/pipe-cd/pipecd/releases/download" · github.com/pipe-cd/[email protected]/pkg/app/launcher/cmd/launcher/launcher.go
mediumRemote Payloadmatched "curl " · github.com/pipe-cd/[email protected]/pkg/app/piped/toolregistry/tool_darwin.go
mediumRemote Payloadmatched "curl " · github.com/pipe-cd/[email protected]/pkg/app/piped/toolregistry/tool_linux.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.56.1-0.20260607075416-dcc037e06c3bHigh risk362026-06-08
v0.56.1-0.20260606214646-85d8d2438871High risk362026-06-07
v0.56.1-0.20260603121307-caf9d6986999High risk362026-06-05
v0.0.0-20260603121307-caf9d6986999High risk362026-06-05
v0.56.1-0.20260603073723-04f2b643c7e5High risk362026-06-04
v0.0.0-20260603073723-04f2b643c7e5High risk362026-06-04
v0.56.1-0.20260602072047-bb7f663b1b27High risk362026-06-03
v0.0.0-20260602072047-bb7f663b1b27High risk362026-06-03
v0.56.1-0.20260601060859-33c214313caeHigh risk362026-06-02
v0.0.0-20260601060859-33c214313caeHigh risk362026-06-02
v0.56.1-0.20260530221654-0d71fd0a692fHigh risk362026-05-31
v0.56.1-0.20260530004416-33034425eb6dReview362026-05-31
v0.56.1-0.20260528025734-166c804a53acHigh risk362026-05-30
v0.0.0-20260528025734-166c804a53acHigh risk362026-05-30

Block this in CI

PkgRadar gates github.com/pipe-cd/pipecd (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/pipe-cd/[email protected]