PkgRadar

Go modules · proxy.golang.org

github.com/pulumi/coconut

Remote Payload, Credential file access

Why PkgRadar flagged v0.15.1-rc1

SeveritySignalEvidence
mediumRemote Payload

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v3.23.0+incompatibleLow risk02026-06-28
v3.61.0+incompatibleLow risk02026-06-28
v3.117.0+incompatibleLow risk02026-06-28
v0.15.1-rc1Review152026-06-28
v3.113.0+incompatibleLow risk02026-06-28
v0.10.0-rc2Review32026-06-28
v0.15.3Review152026-06-28
v0.9.12Review32026-06-28
v3.201.0+incompatibleLow risk02026-06-28
v3.183.0+incompatibleLow risk02026-06-28
v3.83.0+incompatibleLow risk02026-06-28
v2.23.0+incompatibleLow risk02026-06-28
v2.18.2+incompatibleLow risk02026-06-28
v0.15.3-devReview152026-06-28
v3.129.0+incompatibleLow risk02026-06-28
v1.7.0Review152026-06-28
v0.11.2Review32026-06-28
v0.16.3Review152026-06-28
v3.199.0+incompatibleLow risk02026-06-28
v3.33.0+incompatibleLow risk02026-06-28
v3.6.0+incompatibleLow risk02026-06-28
v3.157.0+incompatibleLow risk02026-06-28
v0.12.1Review32026-06-28
v0.11.2-rc2Review32026-06-28
v3.100.0+incompatibleLow risk02026-06-28
v3.40.0+incompatibleLow risk02026-06-28
v0.12.3Review32026-06-28
v3.236.0+incompatibleLow risk02026-06-28
v0.15.0Review152026-06-28
v0.16.3-rc2Review152026-06-28
v3.10.3+incompatibleLow risk02026-06-28
v0.12.1-rc2Review32026-06-28
v1.3.0Review152026-06-28
v3.66.0+incompatibleLow risk02026-06-28
v3.36.0+incompatibleLow risk02026-06-28
v1.9.0Review272026-06-28
v3.40.0-alpha.1662093088+incompatibleLow risk02026-06-28
v3.64.0+incompatibleLow risk02026-06-28
v3.248.1-0.20260626174554-d50fd4e70529+incompatibleLow risk02026-06-27
v1.14.0Review32026-06-27
v3.43.0+incompatibleLow risk02026-06-27
v3.248.0+incompatibleLow risk02026-06-27
v1.14.1Review32026-06-27

Block this in CI

PkgRadar gates github.com/pulumi/coconut (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/pulumi/[email protected]
github.com/pulumi/coconut — Go modules security scan | PkgRadar