PkgRadar

Go modules · proxy.golang.org

github.com/shik3i/koalapull

Remote Payload: matched "github.com/BtbN/FFmpeg-Builds/releases/download"

Why PkgRadar flagged v0.5.1

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/BtbN/FFmpeg-Builds/releases/download" · github.com/shik3i/[email protected]/dependency_security.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.5.1Review122026-06-09
v0.5.3Review122026-06-09
v0.6.0Review122026-06-09
v0.6.1Review122026-06-09
v0.6.2Review122026-06-09
v0.3.6Review122026-06-04
v0.3.4Review122026-06-04
v0.3.3Review122026-06-04
v0.3.2Review122026-06-04
v0.2.1Review122026-06-04
v0.2.0Review122026-06-04
v0.1.6-0.20260602222101-583cdd3c3d2dReview122026-06-03
v0.1.3Review122026-06-03
v0.1.2Review122026-06-03
v0.1.5Review122026-06-03
v0.1.4Review122026-06-03
v0.1.0Review122026-06-03

Block this in CI

PkgRadar gates github.com/shik3i/koalapull (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/shik3i/[email protected]