PkgRadar

Go modules · proxy.golang.org

github.com/yeetrun/yeet

Remote Payload: matched "github.com/yeetrun/yeet-vm-images/releases/download"

Why PkgRadar flagged v0.7.2

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/yeetrun/yeet-vm-images/releases/download" · github.com/yeetrun/[email protected]/pkg/catch/vm_image_registry.go
mediumRemote Payloadmatched "curl " · github.com/yeetrun/[email protected]/pkg/yeet/init_download.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.7.2Review342026-06-13
v0.7.1Review342026-06-13
v0.7.0Review342026-06-11
v0.6.16Review342026-06-11
v0.6.13Review342026-06-11
v0.6.11Review342026-06-10
v0.6.6Review342026-06-10
v0.6.10Review342026-06-09
v0.6.9Review342026-06-09
v0.6.8Review342026-06-09
v0.6.7Review342026-06-09
v0.5.13Review222026-06-08
v0.5.13-0.20260607004613-37717670305cReview222026-06-08
v0.5.12Review222026-06-08
v0.5.11Review222026-06-07
v0.5.7Review222026-06-07
v0.5.10Review222026-06-07
v0.5.8Review222026-06-07
v0.5.3Review222026-06-06
v0.5.2Review222026-06-06
v0.5.1Review222026-06-06
v0.5.0Review222026-06-06
v0.3.3Review122026-05-30

Block this in CI

PkgRadar gates github.com/yeetrun/yeet (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/yeetrun/[email protected]