PkgRadar

Go modules · proxy.golang.org

github.com/wesm/kata

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v0.0.0-20260616000009-c78d3ea3c7d8

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/wesm/[email protected]/pkg/client/generated/generate.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260616000009-c78d3ea3c7d8Review152026-06-17
v0.0.0-20260613205545-aed88a31480cReview152026-06-15
v0.0.0-20260613191415-7fbf9a2608b2Review152026-06-14
v0.0.0-20260613175603-1da9be7c0bcbReview152026-06-14
v0.0.0-20260611154708-3ac7870815f6Review152026-06-13
v0.0.0-20260608214055-8756c40e8114Review152026-06-10
v0.0.0-20260605163703-33cfc4b0d459Low risk02026-06-06
v0.0.0-20260604031327-3ec9d2546e38Low risk02026-06-05
v0.0.0-20260603163123-9105662ade33Low risk02026-06-04
v0.0.0-20260602145408-242ea65df6bfLow risk02026-06-04
v0.0.0-20260601203216-1ee4dee9dc31Low risk02026-06-02
v0.0.0-20260601014139-0953428373ceLow risk02026-06-02
v0.0.0-20260530213845-17b43af78a57Low risk02026-06-01
v0.0.0-20260529035749-8ba62dc66f34Low risk02026-05-30
v0.0.0-20260528134725-86952a3beae3Low risk02026-05-29
v0.0.0-20260527135500-c5e9cc760589Review122026-05-29

Block this in CI

PkgRadar gates github.com/wesm/kata (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/wesm/[email protected]