PkgRadar

Go modules · proxy.golang.org

github.com/vectorizedio/redpanda/src/go/rpk

Remote Payload: matched "github.com/tinygo-org/tinygo/releases/download"

Why PkgRadar flagged v0.0.0-20260611230352-65a22a236015

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/tinygo-org/tinygo/releases/download" · github.com/vectorizedio/redpanda/src/go/[email protected]/pkg/cli/transform/buildpack/buildpack.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260611230352-65a22a236015Review122026-06-12
v0.0.0-20260611174256-0077441b9430Review122026-06-12
v0.0.0-20260611162145-5df7185e518fReview122026-06-12
v0.0.0-20260611044734-f52d5b757aafReview122026-06-12
v0.0.0-20260610204357-2e5ae902ae1dReview122026-06-12
v0.0.0-20260610080713-aa4513a0bf7bReview122026-06-11
v0.0.0-20260609170246-988b5873d7e9Review122026-06-10
v0.0.0-20260609151728-f9470d7742fbReview122026-06-10
v0.0.0-20260609070723-c7d8a311dbd0Review122026-06-10
v0.0.0-20260608080219-6d7f89514dccReview122026-06-09
v0.0.0-20260605155141-a7fb8765e0caReview122026-06-06
v0.0.0-20260604215347-5a7b5b7169e2Review122026-06-06
v0.0.0-20260602024316-dd979168fc8aReview122026-06-03
v0.0.0-20260601220357-572b0355ef37Review122026-06-03
v0.0.0-20260601074651-d22fce8fb57dReview122026-06-02
v0.0.0-20260529210221-3cebdf65598fReview122026-05-31
v0.0.0-20260529015856-5b6789bf8fa6Review122026-05-30

Block this in CI

PkgRadar gates github.com/vectorizedio/redpanda/src/go/rpk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/vectorizedio/redpanda/src/go/[email protected]