PkgRadar

Go modules · proxy.golang.org

github.com/ray-project/kuberay

Remote Payload: matched "cURL "

Why PkgRadar flagged v0.0.0-20260613002010-d835f470d099

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/ray-project/[email protected]/kubectl-plugin/pkg/util/validation.go
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/ray-project/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260613002010-d835f470d099Review222026-06-14
v0.3.0-rc.0.0.20260613002010-d835f470d099Review222026-06-14
v0.0.0-20260611145220-178e6c91d536Review222026-06-12
v0.0.0-20260609215855-6918b7999b17Review222026-06-11
v0.0.0-20260609034944-bb181c47f836Review222026-06-10
v0.3.0-rc.0.0.20260604152141-0db4b573eb10Review222026-06-06
v0.0.0-20260604152141-0db4b573eb10Review222026-06-06
v0.3.0-rc.0.0.20260602042044-a284b829f854Review222026-06-03
v0.0.0-20260602042044-a284b829f854Review222026-06-03
v0.3.0-rc.0.0.20260531065822-156391d3d3a2Review222026-06-01
v0.0.0-20260531065822-156391d3d3a2Review222026-06-01
v0.3.0-rc.0.0.20260530000852-137a424ba8beReview222026-05-31
v0.0.0-20260530000852-137a424ba8beReview222026-05-31
v0.0.0-20260528033703-939e2d7af2f6Review222026-05-30

Block this in CI

PkgRadar gates github.com/ray-project/kuberay (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/ray-project/[email protected]