PkgRadar

Go modules · proxy.golang.org

github.com/spore-host/lagotto

Remote Payload

Why PkgRadar flagged v0.47.1

SeveritySignalEvidence
mediumRemote Payloadgithub.com/spore-host/[email protected]/pkg/deploy/deploy.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.43.0Low risk02026-06-21
v0.47.1Review122026-06-21
v0.47.0Review122026-06-21
v0.46.0Review122026-06-21
v0.45.0Review122026-06-21
v0.44.0Low risk02026-06-21
v0.38.1Low risk02026-06-04
v0.38.0Low risk02026-06-03
v0.37.0Low risk02026-06-03
v0.36.2Low risk02026-06-01
v0.36.2-0.20260531012927-526abc08a4a9Low risk02026-06-01
v0.36.0Low risk02026-06-01
v0.36.1Low risk02026-06-01

Block this in CI

PkgRadar gates github.com/spore-host/lagotto (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/spore-host/[email protected]