PkgRadar

Go modules · proxy.golang.org

github.com/score-spec/score-k8s

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged v0.0.0-20260615185531-8724ab16e5bf

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/score-spec/[email protected]/internal/command/init.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260615185531-8724ab16e5bfReview152026-06-17
v0.0.0-20260615143708-adbcd894b1e5Review152026-06-16
v0.0.0-20260609135918-defbdff9fbdfReview152026-06-11
v0.0.0-20260608160206-7df4f58454e5Review152026-06-09
v0.0.0-20260605182515-dc1d96b3f472Review152026-06-08
v0.0.0-20260602192208-747a1ef1b757Review152026-06-03

Block this in CI

PkgRadar gates github.com/score-spec/score-k8s (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/score-spec/[email protected]