PkgRadar

Go modules · proxy.golang.org

github.com/twmb/franz-go

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v1.18.1-0.20260615024848-f17c00130060

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/twmb/[email protected]/generate/main.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.18.1-0.20260615024848-f17c00130060Review152026-06-17
v1.13.2-0.20260615024848-f17c00130060Review152026-06-16
v0.0.0-20260615024848-f17c00130060Review152026-06-16
v1.7.1-0.20260615024340-e2b667d60d9aReview152026-06-16
v1.21.4-0.20260615024340-e2b667d60d9aReview152026-06-16
v1.21.4-0.20260615002433-36f354879e3aReview152026-06-16
v0.0.0-20251016232131-455089a7fa3dReview152026-06-14
v1.20.1-0.20251016232131-455089a7fa3dReview152026-06-14
v1.18.1-0.20260606182254-a0f8f332c495Review152026-06-14
v0.0.0-20260512162242-95d74ab37350Review152026-06-13
v1.1.1-0.20260606182254-a0f8f332c495Review152026-06-08
v1.13.2-0.20260606182254-a0f8f332c495Review152026-06-07
v1.21.3-0.20260606043251-a4af6ec60c21Review152026-06-07
v1.18.1-0.20260605011553-ae33ee986d04Review152026-06-06
v1.13.2-0.20260605011553-ae33ee986d04Review152026-06-06
v0.0.0-20260605011553-ae33ee986d04Review152026-06-06
v1.21.3-0.20260605004928-90071ea753feReview152026-06-06
v0.0.0-20260605004928-90071ea753feReview152026-06-06
v1.19.6-0.20250825095326-1392074d434eReview152026-06-05
v0.0.0-20260218054735-2437c0f42b2eReview152026-06-05
v0.0.0-20241128193306-f66d4957115fReview152026-06-05
v0.0.0-20250120233007-6c955bf9b155Review152026-06-03
v1.18.1-0.20250120233007-6c955bf9b155Review152026-06-03
v1.18.1-0.20260529212035-11b03a277c72Review152026-06-02
v1.21.3-0.20260529212035-11b03a277c72Review152026-06-02
v1.18.1-0.20260515175617-8268a5d078c0Review152026-06-01
v1.14.1-0.20250121001354-6ea03e3a3810Review152026-06-01
v0.0.0-20250512230254-e6a9591b38ebReview152026-06-01
v0.0.0-20250121043053-91dd0e68e166Review152026-05-31
v1.18.2-0.20250121043053-91dd0e68e166Review152026-05-31

Block this in CI

PkgRadar gates github.com/twmb/franz-go (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/twmb/[email protected]