PkgRadar

Go modules · proxy.golang.org

go.platform-mesh.io/platform-mesh

Remote Payload

Why PkgRadar flagged v0.0.0-20260622100928-59d08918c945

SeveritySignalEvidence
mediumRemote Payloadgo.platform-mesh.io/[email protected]/cmd/qbrtool/internal/github/client.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260622100928-59d08918c945Review122026-06-23
v0.0.0-20260622100944-010f91729b05Review122026-06-23
v0.0.0-20260622091408-6d907fb69315Review122026-06-23
v0.0.0-20260618110923-a7e30601e9bdLow risk02026-06-23
v0.0.0-20260622070501-7fc014f7e2e7Review122026-06-23

Block this in CI

PkgRadar gates go.platform-mesh.io/platform-mesh (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go go.platform-mesh.io/[email protected]