PkgRadar

Go modules · proxy.golang.org

github.com/pulumi/pulumi/pkg/v3

Remote Payload: matched "curl "

Why PkgRadar flagged v3.246.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/pulumi/pulumi/pkg/[email protected]/cmd/pulumi/pulumi.go
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/pulumi/pulumi/pkg/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v3.246.0Review272026-06-13
v3.245.1-0.20260609104754-9623e2fac984Review272026-06-10
v3.245.1-0.20260609115539-7308f65a7562Review272026-06-10
v3.245.1-0.20260609083152-e5772627c2b0Review272026-06-10
v3.245.1-0.20260607095642-1ea24115892eReview272026-06-09
v3.245.1-0.20260605130235-5de910beeb8dReview272026-06-06
v3.245.1-0.20260605100848-9758ae9b7834Review272026-06-06
v3.245.1-0.20260605073558-62dc6d4711f9Review272026-06-06
v3.245.1-0.20260605091308-2cd4a00862c0Review272026-06-06
v3.243.1-0.20260602141017-6011fc3842f4Review272026-06-03
v3.243.1-0.20260602084112-bfe1342e84a5Review272026-06-03
v3.243.1-0.20260601140838-7ee50f74df59Review272026-06-02
v3.243.1-0.20260601094256-246a8ce26388Review272026-06-02
v3.212.1-0.20251216094313-0b06a43beaa2Review342026-06-02
v3.243.1-0.20260528163148-2c171966a134Review272026-05-29

Block this in CI

PkgRadar gates github.com/pulumi/pulumi/pkg/v3 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/pulumi/pulumi/pkg/[email protected]