PkgRadar

Go modules · proxy.golang.org

github.com/smartcontractkit/chainlink/v2

Remote Payload: matched "github.com/%s/releases/download"

Why PkgRadar flagged v2.49.1-beta.1

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/%s/releases/download" · github.com/smartcontractkit/chainlink/[email protected]/operator_ui/install.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v2.49.1-beta.1Review122026-06-03
v2.49.1-rc.2Review122026-06-03
v2.49.1-beta.2Review122026-06-03
v2.49.0-beta.1Review122026-06-03
v2.49.0-beta.0Review122026-06-03
v2.49.1-rc.0Review122026-06-03
v2.49.0-rc.0Review122026-06-03
v2.49.1-rc.1Review122026-06-03
v2.49.0Review122026-06-03
v2.49.0-rc.1Review122026-05-29
v2.49.1-beta.0Review122026-05-29
v2.48.0Review122026-05-29

Block this in CI

PkgRadar gates github.com/smartcontractkit/chainlink/v2 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/smartcontractkit/chainlink/[email protected]