PkgRadar

Go modules · proxy.golang.org

github.com/quintush/helm

Remote Payload: matched "wget\n "

Why PkgRadar flagged v2.12.0-rc.1+incompatible

SeveritySignalEvidence
mediumRemote Payloadmatched "wget\n " · github.com/quintush/[email protected]+incompatible/pkg/chartutil/create.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v2.1.0+incompatibleLow risk02026-06-03
v2.10.0-rc.2+incompatibleLow risk02026-06-03
v2.12.0-rc.1+incompatibleReview122026-06-03
v2.4.0+incompatibleLow risk02026-06-03
v2.15.2+incompatibleReview122026-06-03
v2.15.0-rc.2+incompatibleReview122026-06-03
v2.8.0-rc.1+incompatibleLow risk02026-06-03
v2.15.0+incompatibleReview122026-06-03
v2.16.3+incompatibleReview122026-06-03
v2.0.0-alpha.2+incompatibleLow risk02026-06-03
v2.0.0-alpha.5+incompatibleLow risk02026-06-03
v2.0.0-alpha.1+incompatibleLow risk02026-06-03
v1.2.1Low risk02026-06-03
v2.16.7+incompatibleReview122026-06-03

Block this in CI

PkgRadar gates github.com/quintush/helm (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/quintush/[email protected]+incompatible