PkgRadar

Go modules · proxy.golang.org

github.com/siyuan-note/bazaar

Remote Payload: matched "github.com/siyuan-note/icon-sample/releases/download"

Why PkgRadar flagged v0.0.0-20260616044652-1e70283fae58

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/siyuan-note/icon-sample/releases/download" · github.com/siyuan-note/[email protected]/actions/check/example.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/siyuan-note/[email protected]/actions/check/utils.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/siyuan-note/[email protected]/actions/index/main.go
mediumRemote Payloadmatched "curl " · github.com/siyuan-note/[email protected]/go.mod
mediumRemote Payloadmatched "curl " · github.com/siyuan-note/[email protected]/go.sum

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260616044652-1e70283fae58High risk602026-06-17
v0.0.0-20260615184122-3606a34428ccHigh risk602026-06-16
v0.0.0-20260615131829-10f78f32f885High risk602026-06-16
v0.0.0-20260615062806-0f9694edc6c7High risk602026-06-16
v0.0.0-20260614181607-af74150d0757High risk602026-06-15
v0.0.0-20260614142229-055125814780High risk602026-06-15
v0.0.0-20260614115947-94cdbc11da3cHigh risk602026-06-15
v0.0.0-20260613201812-0092a4bc3ddaHigh risk602026-06-14
v0.0.0-20260613161625-f274f73b4370High risk602026-06-14
v0.0.0-20260613111741-dd5f415f9e7eHigh risk602026-06-14
v0.0.0-20260613082332-e12c703a0520High risk602026-06-14
v0.0.0-20260613040920-b636ff58e00eHigh risk602026-06-14
v0.0.0-20260612042034-c659fe276719High risk602026-06-13
v0.0.0-20260611232614-e1e09c23d920High risk602026-06-12
v0.0.0-20260610163629-eb7846aaac9dHigh risk602026-06-11
v0.0.0-20260610122339-f3aeef8b044dHigh risk602026-06-11
v0.0.0-20260610085059-9d6dc01c1795High risk602026-06-11
v0.0.0-20260610040428-a1016c74dc64High risk602026-06-11
v0.0.0-20260609180945-b95a1c609405High risk602026-06-10
v0.0.0-20260609075332-867eb0a37222High risk602026-06-10
v0.0.0-20260608110320-60031fd1a8e1High risk602026-06-09
v0.0.0-20260607140150-f237f373f792High risk602026-06-08
v0.0.0-20260606144413-da4ddede7fe2High risk602026-06-07
v0.0.0-20260606120705-7c1a0ab233acHigh risk602026-06-07
v0.0.0-20260606100734-ba01a044f918High risk602026-06-07
v0.0.0-20260606045530-58c459d9477fHigh risk602026-06-07
v0.0.0-20260605052110-d009225c16bcHigh risk602026-06-06
v0.0.0-20260604182144-b89ea51a567cHigh risk602026-06-05
v0.0.0-20260604153424-5d7258e5bf73High risk602026-06-05
v0.0.0-20260604115723-19b3e97102adHigh risk602026-06-05
v0.0.0-20260604085200-ceb74c6bdc9bHigh risk602026-06-05
v0.0.0-20260604042402-1f80112952fdHigh risk602026-06-05
v0.0.0-20260603234655-52004d134f0fHigh risk602026-06-04
v0.0.0-20260603200704-0b56a50c8e34High risk602026-06-04
v0.0.0-20260603193640-a921a5f2b3b0High risk602026-06-04
v0.0.0-20260603182529-8433ab76352fHigh risk602026-06-04
v0.0.0-20260603144420-d8f2a4a83571High risk602026-06-04
v0.0.0-20260603043925-2d04aeab8f9fHigh risk602026-06-04
v0.0.0-20260602145601-f9e8edd03e50High risk602026-06-03
v0.0.0-20260602104231-2fcc3c1eb650High risk602026-06-03
v0.0.0-20260602055138-791075095797High risk602026-06-03
v0.0.0-20260601060613-1567ec91cbf2High risk602026-06-02
v0.0.0-20260601000924-c4127838c909High risk602026-06-01
v0.0.0-20260531180521-737ba4978d49High risk602026-06-01
v0.0.0-20260531121728-3ac360ecf56cHigh risk602026-06-01
v0.0.0-20260531110019-b379bdf060d5High risk602026-06-01
v0.0.0-20260531083355-03cc2a5872c8High risk602026-06-01
v0.0.0-20260530171201-d8ee595f89d0High risk602026-05-31
v0.0.0-20260530151130-222808a42ab5High risk602026-05-31
v0.0.0-20260530140546-7fa3a5739ad7High risk602026-05-31
v0.0.0-20260530112325-c07d6ba45be2High risk602026-05-31
v0.0.0-20260530094200-abc7401b5ba7Review602026-05-31
v0.0.0-20260530092105-c0494b2441d1Review602026-05-31
v0.0.0-20260530034739-1ef427476b1cReview602026-05-31
v0.0.0-20260529164314-c86d059f5bc8Review602026-05-30
v0.0.0-20260528100946-091232e07fa9High risk602026-05-30
v0.0.0-20260528041323-9a29cd1ef481High risk602026-05-30
v0.0.0-20260529121715-7a51ae78e2baReview602026-05-30
v0.0.0-20260529054255-ce530f554974Review602026-05-30
v0.0.0-20260529040019-e696afed924eReview602026-05-30
v0.0.0-20260528143830-13ab14828abeReview602026-05-29

Block this in CI

PkgRadar gates github.com/siyuan-note/bazaar (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/siyuan-note/[email protected]