PkgRadar

Go modules · proxy.golang.org

github.com/tooppoo/git-kura

Remote Payload: matched "github.com/%s/releases/download"

Why PkgRadar flagged v0.0.4-0.20260617082357-d206d063e007

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/%s/releases/download" · github.com/tooppoo/[email protected]/cmd/git-kura/tools_asset.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.4-0.20260617082357-d206d063e007Review122026-06-18
v0.0.4-0.20260617080845-f85238c69e6bReview122026-06-18
v0.0.4-0.20260617061319-727635f316bcLow risk02026-06-18
v0.0.4-0.20260617061307-03a356b2bad7Low risk02026-06-18
v0.0.4-0.20260617061221-bfd8049f3971Low risk02026-06-18
v0.0.4-0.20260616165609-6a4661b913b7Low risk02026-06-17
v0.0.4-0.20260616165056-d653435405b2Low risk02026-06-17
v0.0.4-0.20260615080218-0f2c2ce7fe32Low risk02026-06-16
v0.0.4-0.20260615075450-345417db43a3Low risk02026-06-16
v0.0.4-0.20260615074754-958feeca7012Low risk02026-06-16
v0.0.4-0.20260615074535-9aaa9ffbcdeaLow risk02026-06-16
v0.0.4-0.20260615071003-e538b29595aaLow risk02026-06-16
v0.0.4-0.20260615054928-aca3b5314220Low risk02026-06-16
v0.0.4-0.20260614161957-3db2ab8d45e5Low risk02026-06-15
v0.0.4-0.20260614153409-7024849a543dLow risk02026-06-15
v0.0.4-0.20260614150242-748bcd108418Low risk02026-06-15
v0.0.4-0.20260614145037-2ace32cbc7d0Low risk02026-06-15
v0.0.4-0.20260614144228-8116e79fa832Low risk02026-06-15
v0.0.4-0.20260614141800-db878ec9cc0fLow risk02026-06-15
v0.0.4-0.20260614130949-3381a6cc87baLow risk02026-06-15
v0.0.4-0.20260614104915-b3548b4c6ef2Low risk02026-06-15
v0.0.4-0.20260614104429-9a120f8809e9Low risk02026-06-15
v0.0.4-0.20260614033206-f4eb9eb42933Low risk02026-06-15
v0.0.4-0.20260614032047-973725eab895Low risk02026-06-15
v0.0.4-0.20260614031143-6e25b3d39e47Low risk02026-06-15
v0.0.4-0.20260614025020-c3ecfe568440Low risk02026-06-15
v0.0.4-0.20260612090918-8384fcb15577Low risk02026-06-13
v0.0.4-0.20260612090805-bedeca692d50Low risk02026-06-13
v0.0.4-0.20260612090834-328b5549f46eLow risk02026-06-13
v0.0.4-0.20260611102901-a3bc8e99a141Low risk02026-06-12
v0.0.4-0.20260611093954-198dee5d3390Low risk02026-06-12
v0.0.4-0.20260611080347-86759e7ec34dLow risk02026-06-12
v0.0.4-0.20260611071136-7811294da378Low risk02026-06-12
v0.0.3Low risk02026-06-11
v0.0.3-0.20260610171336-6326bbfbc015Low risk02026-06-11
v0.0.3-0.20260610154008-0a8c630b0cc7Low risk02026-06-11
v0.0.3-0.20260610152150-a8e3628ae50aLow risk02026-06-11
v0.0.3-0.20260610152031-86ffbc517f7bLow risk02026-06-11
v0.0.3-0.20260610151301-74ba13248deaLow risk02026-06-11
v0.0.3-0.20260610081227-b9ec6058ee19Low risk02026-06-11
v0.0.2Low risk02026-06-11
v0.0.1Low risk02026-06-11
v0.0.0-alphaLow risk02026-06-11
v0.0.2-0.20260610080050-58eb66d3d25dLow risk02026-06-11

Block this in CI

PkgRadar gates github.com/tooppoo/git-kura (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/tooppoo/[email protected]