Go modules · proxy.golang.org
github.com/polymetrics-ai/cli
Shipped Live Secret, Credential file access, Obfuscation Density
Why PkgRadar flagged v0.0.0-20260701150637-e28260ffb333
| Severity | Signal | Evidence |
|---|---|---|
| high | Shipped Live Secret | — |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v0.0.0-20260701150637-e28260ffb333 | High risk | 63 | 2026-07-02 |
v0.0.0-20260701145558-fd8dc1b6bde6 | High risk | 63 | 2026-07-02 |
v0.0.0-20260701142937-ab7fa853939d | High risk | 63 | 2026-07-02 |
v0.0.0-20260701140335-ccd417a1bc98 | High risk | 63 | 2026-07-02 |
v0.0.0-20260701130504-a3d390354dcf | High risk | 63 | 2026-07-02 |
Block this in CI
pkgradar gate --ecosystem go github.com/polymetrics-ai/[email protected]