PkgRadar

Go modules · proxy.golang.org

github.com/superplanehq/superplane

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged v0.25.2-0.20260609214556-4d511c245ca6

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/superplanehq/[email protected]/pkg/agents/anthropic/resources.go
mediumRemote Payloadmatched "github.com/superplanehq/superplane/releases/download" · github.com/superplanehq/[email protected]/pkg/cli/upgrade.go
mediumRemote Payloadmatched "cURL " · github.com/superplanehq/[email protected]/pkg/integrations/azure/actions.go
mediumRemote Payloadmatched "cURL " · github.com/superplanehq/[email protected]/pkg/integrations/azure/arm_client.go
mediumRemote Payloadmatched "cURL " · github.com/superplanehq/[email protected]/pkg/integrations/gcp/artifactregistry/on_artifact_analysis.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.25.2-0.20260609214556-4d511c245ca6High risk752026-06-11
v0.25.1High risk752026-06-11
v0.25.1-0.20260608185135-48cadadca65eHigh risk752026-06-09
v0.25.0High risk752026-06-09
v0.24.1-0.20260601182257-79a43ec0d3f5High risk752026-06-03
v0.24.0High risk752026-06-03
v0.23.1-0.20260529025458-f91c5f78004fReview752026-05-30
v0.23.0Review752026-05-30

Block this in CI

PkgRadar gates github.com/superplanehq/superplane (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/superplanehq/[email protected]