PkgRadar

Go modules · proxy.golang.org

github.com/sumnerevans/tracktime

Remote Payload: matched "api.github.com/graphql"

Why PkgRadar flagged v1.0.2-0.20260603003504-0dba05d8038d

SeveritySignalEvidence
mediumRemote Payloadmatched "api.github.com/graphql" · github.com/sumnerevans/[email protected]/internal/resolver/github.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.9.4Low risk02026-06-11
v0.9.20Low risk02026-06-11
v0.10.0Low risk02026-06-11
v0.9.5Low risk02026-06-11
v0.9.16Low risk02026-06-11
v0.9.2Low risk02026-06-11
v0.9.14Low risk02026-06-11
v0.9.15Low risk02026-06-11
v0.9.3Low risk02026-06-11
v0.9.12Low risk02026-06-11
v1.0.2-0.20260603003504-0dba05d8038dReview122026-06-11

Block this in CI

PkgRadar gates github.com/sumnerevans/tracktime (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/sumnerevans/[email protected]