PkgRadar

Go modules · proxy.golang.org

github.com/tokiwa-software/fuzion

Remote Payload: matched "wget "

Why PkgRadar flagged v0.0.0-20260526074707-82fa737eff28

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · github.com/tokiwa-software/[email protected]/bin/windows_install_boehm_gc.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260612131630-25a9209f64f0Low risk02026-06-14
v0.0.0-20260611114459-7935358ec8b7Low risk02026-06-13
v0.0.0-20260610153203-101adae8b404Low risk02026-06-11
v0.0.0-20260605072611-3b432a35e2d1Low risk02026-06-07
v0.0.0-20260529090410-e47bf8e1569eLow risk02026-05-31
v0.0.0-20260526074707-82fa737eff28Review122026-05-29

Block this in CI

PkgRadar gates github.com/tokiwa-software/fuzion (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/tokiwa-software/[email protected]