PkgRadar

Go modules · proxy.golang.org

gitlab.com/data-custodian/custodian/tools/quitsh

Go Mod Replace Local: go.mod replace directive redirects to a local filesystem path — non-portable / dev-time only.

Why PkgRadar flagged v0.0.0-20260610072030-447daae0132f

SeveritySignalEvidence
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · gitlab.com/data-custodian/custodian/tools/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260610072030-447daae0132fReview102026-06-11
v0.0.0-20260609121845-91abac500463Review102026-06-10
v0.0.0-20260609115949-50d3802d2011Review102026-06-10
v0.0.0-20260609050105-6f3243289187Review102026-06-10
v0.0.0-20260605152505-adedfb96b527Review102026-06-08
v0.0.0-20260604163324-c28eba26253bReview102026-06-05
v0.0.0-20260603144008-59757108a682Review102026-06-04
v0.0.0-20260603111040-b5bfd4f35d9eReview102026-06-04
v0.0.0-20260603094304-ab9185c8a779Review102026-06-04
v0.0.0-20260602175018-ce58f6b8f46bReview102026-06-03
v0.0.0-20260602173215-df6d1ec49fa3Review102026-06-03
v0.0.0-20260602165900-f950cf61d88fReview102026-06-03
v0.0.0-20260601074617-9b9270a22eeeReview102026-06-02

Block this in CI

PkgRadar gates gitlab.com/data-custodian/custodian/tools/quitsh (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go gitlab.com/data-custodian/custodian/tools/[email protected]