PkgRadar

Go modules · proxy.golang.org

github.com/ti-community-infra/test-infra

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged v0.0.0-20240410081331-9f9924cee00e

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/ti-community-infra/[email protected]/experiment/coverage/apicoverage.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/ti-community-infra/[email protected]/kubetest/aks.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/ti-community-infra/[email protected]/kubetest/aksengine.go
mediumRemote Payloadmatched "github.com/kubernetes-sigs/kind/releases/download" · github.com/ti-community-infra/[email protected]/kubetest/kind/kind.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20240410081331-9f9924cee00eHigh risk1482026-06-04
v1.0.2High risk1142026-06-04
v1.0.1High risk1142026-06-04
v1.0.3High risk1142026-06-04
v1.0.0High risk1142026-06-04

Block this in CI

PkgRadar gates github.com/ti-community-infra/test-infra (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/ti-community-infra/[email protected]