PkgRadar

Go modules · proxy.golang.org

github.com/runatlantis/atlantis

Remote Payload: matched "github.com/open-policy-agent/conftest/releases/download"

Why PkgRadar flagged v0.44.1-0.20260614160537-449737c3b2a0

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/open-policy-agent/conftest/releases/download" · github.com/runatlantis/[email protected]/server/core/runtime/policy/conftest_client.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/runatlantis/[email protected]/server/events/vcs/azuredevops/client.go
mediumRemote Payloadmatched "api.github.com/graphql" · github.com/runatlantis/[email protected]/server/events/vcs/github/client.go
mediumRemote Payloadmatched "cURL " · github.com/runatlantis/[email protected]/testdrive/utils.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.44.1-0.20260614160537-449737c3b2a0High risk482026-06-15
v0.0.0-20260614160537-449737c3b2a0High risk482026-06-15
v0.44.1-0.20260612010711-ffacfba754a0High risk482026-06-13
v0.44.1-0.20260611122831-0717ac2314f9High risk482026-06-12
v0.0.0-20260611122831-0717ac2314f9High risk482026-06-12
v0.44.0High risk482026-06-11
v0.43.1-0.20260604163249-daec8d509383High risk482026-06-06
v0.0.0-20260604163249-daec8d509383High risk482026-06-06
v0.0.0-20260604083612-05216e92ae9eHigh risk482026-06-05
v0.0.0-20260604052928-a39464f32247High risk482026-06-05
v0.43.1-0.20260604034729-7d8aff76f423High risk482026-06-05
v0.0.0-20260604034729-7d8aff76f423High risk482026-06-05
v0.43.1-0.20260604024022-57b10985f5ceHigh risk482026-06-05
v0.0.0-20260604024022-57b10985f5ceHigh risk482026-06-05
v0.0.0-20260604001900-d33606a14441High risk482026-06-05
v0.43.1-0.20260603232317-a2f9943e1506High risk482026-06-05
v0.0.0-20260603232317-a2f9943e1506High risk482026-06-05
v0.43.1-0.20260531032739-a8b0b9d5f383High risk482026-06-01
v0.0.0-20260531032739-a8b0b9d5f383High risk482026-06-01
v0.43.1-0.20260529060315-b0e942dd0146Review482026-05-30
v0.0.0-20260529060315-b0e942dd0146Review482026-05-30

Block this in CI

PkgRadar gates github.com/runatlantis/atlantis (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/runatlantis/[email protected]