PkgRadar

Go modules · proxy.golang.org

github.com/sipsma/dagger

Remote Payload: matched "curl "

Why PkgRadar flagged v0.3.10

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/sipsma/[email protected]/cmd/dagger/run.go
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/sipsma/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.3.10Review252026-06-10
v0.3.1Review102026-06-10
v0.3.13Review252026-06-10
v0.3.12Review252026-06-10
v0.17.0-llm.4Review292026-06-10
v0.3.6Review202026-06-10
v0.17.0-llm.6Review292026-06-10
v0.3.9Review252026-06-10
v0.20.5Review442026-06-09
v0.20.6Review442026-06-09
v0.20.2Review442026-06-09
v0.20.1Review392026-06-09
v0.19.10Review392026-06-09
v0.19.8Review392026-06-09
v0.20.0Review392026-06-09
v0.19.7Review392026-06-09
v0.16.3Review292026-06-09
v0.18.10Review342026-06-09
v0.18.5Review342026-06-09
v0.18.1Review292026-06-09
v0.17.1Review292026-06-09
v0.18.0Review292026-06-09
v0.15.4Review292026-06-09
v0.15.2Review292026-06-09
v0.14.0Review322026-06-09
v0.13.2Review322026-06-09
v0.13.6Review322026-06-09
v0.12.6Review322026-06-09
v0.13.1Review322026-06-09
v0.3.2Review102026-06-09
v0.20.3Review442026-06-09
v0.18.9Review342026-06-09
v0.12.5Review322026-06-09
v0.12.2Review272026-06-09
v0.19.4Review392026-06-09
v0.20.8Review442026-06-09
v0.12.0Review272026-06-09
v0.12.1Review272026-06-09
v0.10.3Review372026-06-09
v0.11.4Review372026-06-09
v0.10.2Review372026-06-09
v0.13.3Review322026-06-09
v0.8.8Review252026-06-09
v0.15.3Review292026-06-09
v0.9.4Review252026-06-09
v0.9.3Review252026-06-09
v0.8.7Review252026-06-09
v0.6.4Review252026-06-09
v0.12.4Review322026-06-09
v0.11.0Review372026-06-09
v0.17.0Review292026-06-09
v0.6.0Review252026-06-09
v0.4.2Review282026-06-09
v0.4.1Review282026-06-09
v0.3.0Review102026-06-09
v0.10.1Review372026-06-08
v0.13.0Review322026-06-08
v0.9.11Review372026-06-08
v0.19.2Review392026-06-08
v0.21.1-0.20260530020212-1b8fffff53f6Review442026-05-31
v0.11.7Review272026-05-31
v0.21.0Review442026-05-31
v0.0.0-20260530020212-1b8fffff53f6Review442026-05-31

Block this in CI

PkgRadar gates github.com/sipsma/dagger (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/sipsma/[email protected]