PkgRadar

Go modules · proxy.golang.org

gitlab.com/loranna/venvironment

Go Mod Replace Local: go.mod replace directive redirects to a local filesystem path — non-portable / dev-time only.

Why PkgRadar flagged v0.1.5

SeveritySignalEvidence
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · gitlab.com/loranna/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.12.163Low risk02026-06-06
v0.10.121Low risk02026-06-06
v0.2.11Low risk02026-06-06
v0.8.88Low risk02026-06-06
v0.1.5Review102026-06-06
v0.12.168Low risk02026-06-06
v0.10.140Low risk02026-06-06
v0.5.42Low risk02026-06-06
v0.10.137Low risk02026-06-06
v0.7.68Low risk02026-06-06
v0.6.61Low risk02026-06-06
v0.10.133Low risk02026-06-06
v0.9.91Low risk02026-06-06
v0.9.93Low risk02026-06-06
v0.11.150Low risk02026-06-06
v0.11.155Low risk02026-06-06
v0.11.146Low risk02026-06-06
v0.11.144Low risk02026-06-06
v0.10.138Low risk02026-06-06
v0.11.145Low risk02026-06-06
v0.11.159Low risk02026-06-06
v0.10.141Low risk02026-06-06
v0.3.24Low risk02026-06-06
v0.6.53Low risk02026-06-06
v0.11.158Low risk02026-06-06

Block this in CI

PkgRadar gates gitlab.com/loranna/venvironment (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go gitlab.com/loranna/[email protected]