PkgRadar

Go modules · proxy.golang.org

github.com/vulnetix/cli/v3

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged v3.12.1-0.20260601050836-d856927e6e19

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/vulnetix/cli/[email protected]/cmd/sarif_persist.go
mediumRemote Payloadmatched "cURL " · github.com/vulnetix/cli/[email protected]/cmd/vdb.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/vulnetix/cli/[email protected]/internal/license/registries.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v3.12.1-0.20260601050836-d856927e6e19High risk362026-06-02
v3.12.0High risk362026-06-02
v3.11.0High risk362026-06-02
v3.10.3-0.20260601022714-6661a85b72eeHigh risk362026-06-02
v3.10.2High risk362026-06-02
v3.10.2-0.20260531153400-23612da0b8ccHigh risk362026-06-01
v3.10.1High risk362026-06-01
v3.10.1-0.20260530160248-7da5a4e7dd5aHigh risk362026-05-31
v3.10.0High risk362026-05-31
v3.9.2-0.20260529131055-b36f9e16108cReview362026-05-30
v3.9.1Review362026-05-30
v3.9.0Review362026-05-30
v3.8.2Review362026-05-30
v3.8.1Review362026-05-30
v3.8.1-0.20260528150620-66356ce2cba8Review362026-05-29
v3.8.0Review362026-05-29

Block this in CI

PkgRadar gates github.com/vulnetix/cli/v3 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/vulnetix/cli/[email protected]