Go modules · proxy.golang.org
github.com/smartcontractkit/chainlink/deployment
Remote Payload: matched "raw.githubusercontent.com"
Why PkgRadar flagged v0.0.0-20260602204426-63d7423fafb5
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "raw.githubusercontent.com" · github.com/smartcontractkit/chainlink/[email protected]/ccip/changeset/aptos/cs_deploy_aptos_chain.go |
| medium | Remote Payload | matched "cURL " · github.com/smartcontractkit/chainlink/[email protected]/cre/cmd/fetch-ocr3-config/main.go |
| medium | Remote Payload | matched "CURL " · github.com/smartcontractkit/chainlink/[email protected]/environment/devenv/fast-filler.go |
| medium | Go Mod Replace Local | go.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · github.com/smartcontractkit/chainlink/[email protected]/go.mod |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v0.0.0-20260602204426-63d7423fafb5 | High risk | 46 | 2026-06-03 |
v0.0.0-20260602142951-d0257c8e045e | High risk | 46 | 2026-06-03 |
v0.0.0-20260602120939-7426cc78283c | High risk | 46 | 2026-06-03 |
v0.0.0-20260601214114-c5dbe0633bf7 | High risk | 46 | 2026-06-02 |
v0.0.0-20260601151340-86881e5bc869 | High risk | 46 | 2026-06-02 |
v0.0.0-20260601122428-1cb63f7c1476 | High risk | 46 | 2026-06-02 |
v0.0.0-20260601091614-e48b85574780 | High risk | 46 | 2026-06-02 |
v0.0.0-20260528111936-4df618f21e9c | High risk | 46 | 2026-05-30 |
v0.0.0-20260528101724-4615d67bdc27 | High risk | 46 | 2026-05-30 |
v0.0.0-20260528024658-4ab71c4ae255 | High risk | 46 | 2026-05-30 |
v0.0.0-20260529143830-9e6be79b8f13 | Review | 46 | 2026-05-30 |
v0.0.0-20260528204816-bbece57796e4 | Review | 46 | 2026-05-29 |
v0.0.0-20260528180913-89d6e0c88c1d | Review | 46 | 2026-05-29 |
v0.0.0-20260528165543-fd4437f446aa | Review | 46 | 2026-05-29 |
v0.0.0-20260528163654-5f93f315350a | Review | 46 | 2026-05-29 |
Block this in CI
pkgradar gate --ecosystem go github.com/smartcontractkit/chainlink/[email protected]