PkgRadar

Go modules · proxy.golang.org

github.com/sapcc/go-makefile-maker

Remote Payload: matched "wget "

Why PkgRadar flagged v0.0.0-20260609134435-ed97f8ca1cc2

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · github.com/sapcc/[email protected]/internal/dockerfile/docker.go
mediumRemote Payloadmatched "curl " · github.com/sapcc/[email protected]/internal/makefile/makefile.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260609134435-ed97f8ca1cc2Review242026-06-11
v0.0.0-20260605080540-1c3c904f26ceReview242026-06-06
v0.0.0-20260605080059-cde9d033041aReview242026-06-06
v0.0.0-20260528190206-375327f4d47eReview242026-05-29
v0.0.0-20260528135046-5428319004b7Review242026-05-29
v0.0.0-20260528125730-6429976a88a5Review242026-05-29

Block this in CI

PkgRadar gates github.com/sapcc/go-makefile-maker (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/sapcc/[email protected]