Go modules · proxy.golang.org
go.jetpack.io/devbox
Remote Payload: matched "raw.githubusercontent.com"
Why PkgRadar flagged v0.0.0-20260609223142-11322d5ba0e4
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "raw.githubusercontent.com" · go.jetpack.io/[email protected]/internal/devconfig/config.go |
| medium | Remote Payload | matched "raw.githubusercontent.com" · go.jetpack.io/[email protected]/internal/plugin/github.go |
| medium | Remote Payload | matched "curl " · go.jetpack.io/[email protected]/internal/vercheck/vercheck.go |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v0.0.0-20260609223142-11322d5ba0e4 | High risk | 46 | 2026-06-11 |
v0.0.0-20260606002939-75f5ed84a3ed | High risk | 46 | 2026-06-08 |
v0.0.0-20260601221703-35d57a3734d0 | High risk | 46 | 2026-06-04 |
v0.0.0-20260601040213-8816d61cfe97 | High risk | 46 | 2026-06-02 |
Block this in CI
pkgradar gate --ecosystem go go.jetpack.io/[email protected]