PkgRadar

Go modules · proxy.golang.org

github.com/shuffle/shuffle-shared/app_upload

Go Mod Replace Local: go.mod replace directive redirects to a local filesystem path — non-portable / dev-time only.

Why PkgRadar flagged v0.0.0-20260615132629-eba0ff5229d9

SeveritySignalEvidence
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/shuffle/shuffle-shared/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260615132629-eba0ff5229d9Review102026-06-17
v0.0.0-20260611192748-8fd775cc5feaReview102026-06-13
v0.0.0-20260608132545-3ef3996243ffReview102026-06-09
v0.0.0-20260604125839-6a14d41693c3Review102026-06-07
v0.0.0-20260603063248-4c71051ebb7dReview102026-06-04
v0.0.0-20260528222018-1cdfb3e1e337Review102026-05-30

Block this in CI

PkgRadar gates github.com/shuffle/shuffle-shared/app_upload (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/shuffle/shuffle-shared/[email protected]