PkgRadar

Go modules · proxy.golang.org

go.kenn.io/kata

Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.

Why PkgRadar flagged v0.0.0-20260609191001-40f0007e1007

SeveritySignalEvidence
mediumGo Generate Shell//go:generate directive shells out to curl/wget/bash — runs during `go generate`. · go.kenn.io/[email protected]/pkg/client/generated/generate.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260609191001-40f0007e1007Review152026-06-11
v0.0.0-20260609123621-5c183cd961a4Review152026-06-10
v0.0.0-20260605122453-50378b68397fLow risk02026-06-06
v0.0.0-20260605010858-cc3909e57e56Low risk02026-06-06
v0.0.0-20260604031327-3ec9d2546e38Low risk02026-06-05
v0.0.0-20260603163123-9105662ade33Low risk02026-06-04
v0.0.0-20260602010627-0dfd8cacd449Low risk02026-06-03
v0.0.0-20260601171931-b3c441629824Low risk02026-06-02
v0.0.0-20260601131332-e88680a6fd62Low risk02026-06-02
v0.0.0-20260601014139-0953428373ceLow risk02026-06-02
v0.0.0-20260531135227-dc53364455a4Low risk02026-06-01
v0.0.0-20260531121413-56953682cca2Low risk02026-06-01
v0.0.0-20260530213845-17b43af78a57Low risk02026-06-01
v0.0.0-20260529212010-69a170c66a94Low risk02026-05-31
v0.0.0-20260529035749-8ba62dc66f34Low risk02026-05-30
v0.0.0-20260528225857-dc54a2251a1eLow risk02026-05-29
v0.0.0-20260528211021-9e390ca18017Low risk02026-05-29
v0.0.0-20260528134725-86952a3beae3Low risk02026-05-29

Block this in CI

PkgRadar gates go.kenn.io/kata (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go go.kenn.io/[email protected]