PkgRadar

Go modules · proxy.golang.org

github.tiyicn.workers.dev/pipe-cd/pipecd

Remote Payload: matched "github.com/pipe-cd/pipecd/releases/download"

Why PkgRadar flagged v0.45.3-rc0

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/pipe-cd/pipecd/releases/download" · github.tiyicn.workers.dev/pipe-cd/[email protected]/pkg/app/launcher/cmd/launcher/launcher.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.tiyicn.workers.dev/pipe-cd/[email protected]/pkg/app/pipectl/cmd/quickstart/quickstart.go
mediumRemote Payloadmatched "curl " · github.tiyicn.workers.dev/pipe-cd/[email protected]/pkg/app/pipectl/cmd/quickstart/tool_darwin.go
mediumRemote Payloadmatched "curl " · github.tiyicn.workers.dev/pipe-cd/[email protected]/pkg/app/pipectl/cmd/quickstart/tool_linux.go
mediumRemote Payloadmatched "curl " · github.tiyicn.workers.dev/pipe-cd/[email protected]/pkg/app/piped/toolregistry/tool_darwin.go
mediumRemote Payloadmatched "curl " · github.tiyicn.workers.dev/pipe-cd/[email protected]/pkg/app/piped/toolregistry/tool_linux.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.45.3-rc0High risk722026-06-14
v0.47.0High risk742026-06-14
v0.34.0High risk362026-06-14
v0.49.0High risk722026-06-14
v0.45.3High risk722026-06-14
v0.45.4-rc3High risk722026-06-14
v0.46.0-rc0High risk722026-06-14
v0.50.1-rc2High risk482026-06-14
v0.24.3High risk362026-06-14
v0.25.1High risk362026-06-14
v0.40.0High risk722026-06-14
v0.14.0Review242026-06-14
v0.50.1-rc4High risk482026-06-14
v0.1.5Review242026-06-14
v0.48.6High risk742026-06-14
v0.51.0-rc0High risk482026-06-14
v0.47.3-rc0High risk742026-06-14
v0.0.2Review242026-06-14
v0.3.0Review242026-06-14
v0.48.4High risk742026-06-14
v0.45.4-rc2High risk722026-06-14
v0.13.2Review242026-06-14
v0.44.2High risk722026-06-14
v0.13.0Review242026-06-14
v0.45.2High risk722026-06-14
v0.46.0-rc2High risk722026-06-14
v0.10.1Review242026-06-14
v0.20.2High risk362026-06-14
v0.48.8High risk742026-06-14
v0.37.1High risk482026-06-14
v0.48.0-rc0High risk742026-06-14
v0.45.4-rc1High risk722026-06-14
v0.25.0High risk362026-06-14
v0.44.0High risk722026-06-14
v0.37.0High risk482026-06-14
v0.1.2Review242026-06-14
v0.51.3High risk482026-06-14
v0.51.3-rc0High risk482026-06-14
v0.51.4-rc0High risk482026-06-14
v0.52.0High risk362026-06-14
v0.52.1High risk362026-06-14
v0.54.0High risk362026-06-14
v0.54.1High risk362026-06-14
v0.54.0-rc1High risk362026-06-14
v0.54.1-rc0High risk362026-06-14
v0.54.2High risk362026-06-14
v0.55.1-rc0High risk362026-06-14
v0.55.1-rc1High risk362026-06-14
v0.6.0Review242026-06-14
v0.7.0Review242026-06-14
v0.7.1Review242026-06-14
v0.7.2Review242026-06-14
v0.7.5Review242026-06-14
v0.7.6Review242026-06-14
v0.8.0Review292026-06-14
v0.9.0Review292026-06-14
v0.9.10-1-8609c84Review242026-06-14
v0.9.10-1-v0.9.10-1-8609c84Review292026-06-14
v0.9.11Review292026-06-14
v0.9.10-2-8609c84Review292026-06-14
v0.9.12Review242026-06-14
v0.9.13Review242026-06-14
v0.9.14Review242026-06-14
v0.9.15Review242026-06-14
v0.9.16Review242026-06-14
v0.9.17Review242026-06-14
v0.9.4Review292026-06-14

Block this in CI

PkgRadar gates github.tiyicn.workers.dev/pipe-cd/pipecd (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.tiyicn.workers.dev/pipe-cd/[email protected]