PkgRadar

Go modules · proxy.golang.org

github.com/zeroroot-ai/sdk

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged v0.141.0

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/zeroroot-ai/[email protected]/sarif.go
mediumCredential file accessmatched "id_rsa" · github.com/zeroroot-ai/[email protected]/codegen/git/credentials.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.141.0Review272026-06-10
v0.140.0Review272026-06-10
v0.139.0Review272026-06-10
v0.138.0Review272026-06-10
v0.137.0Review272026-06-06
v0.136.0Review272026-06-06
v0.135.0Review272026-06-06
v0.133.0Review272026-06-04
v0.132.0Review272026-06-04
v0.130.0Review272026-06-02
v0.129.1Review272026-06-02
v0.128.0Review222026-06-01
v0.125.0Review222026-05-30

Block this in CI

PkgRadar gates github.com/zeroroot-ai/sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/zeroroot-ai/[email protected]