PkgRadar

Go modules · proxy.golang.org

k8s.io/kops

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged v0.0.0-20260608155551-551a385517e3

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · k8s.io/[email protected]/channels/pkg/cmd/apply_channel.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · k8s.io/[email protected]/pkg/apis/kops/channel.go
mediumRemote Payloadmatched "github.com/kubernetes/kops/releases/download" · k8s.io/[email protected]/pkg/assets/mirrors.go
mediumRemote Payloadmatched "curl " · k8s.io/[email protected]/pkg/model/resources/nodeup.go
mediumRemote Payloadmatched "github.com/containernetworking/plugins/releases/download" · k8s.io/[email protected]/pkg/nodemodel/wellknownassets/cni.go
mediumRemote Payloadmatched "github.com/containerd/containerd/releases/download" · k8s.io/[email protected]/pkg/nodemodel/wellknownassets/containerd.go
mediumRemote Payloadmatched "github.com/kubernetes-sigs/cri-tools/releases/download" · k8s.io/[email protected]/pkg/nodemodel/wellknownassets/crictl.go
mediumRemote Payloadmatched "github.com/containerd/nerdctl/releases/download" · k8s.io/[email protected]/pkg/nodemodel/wellknownassets/nerdctl.go
mediumRemote Payloadmatched "github.com/opencontainers/runc/releases/download" · k8s.io/[email protected]/pkg/nodemodel/wellknownassets/runc.go
mediumCredential file accessmatched ".ssh/" · k8s.io/[email protected]/cmd/kops/update_cluster.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260608155551-551a385517e3High risk1492026-06-09
v1.36.0-alpha.1.0.20260608121546-02c418ff89acHigh risk1492026-06-09
v0.0.0-20260608121546-02c418ff89acHigh risk1492026-06-09
v1.36.0-alpha.1.0.20260608082238-2f7a60d09e25High risk1492026-06-09
v0.0.0-20260608082238-2f7a60d09e25High risk1492026-06-09
v1.36.0-alpha.1.0.20260608004630-82d177975f33High risk1492026-06-09
v0.0.0-20260608004630-82d177975f33High risk1492026-06-09
v1.36.0-alpha.1.0.20260607093431-a1f94fc06db1High risk1492026-06-08
v1.36.0-alpha.1.0.20260606080631-e6044a562e92High risk1492026-06-07
v1.36.0-alpha.1.0.20260606042030-146400d00dd5High risk1492026-06-07
v0.0.0-20260606042030-146400d00dd5High risk1492026-06-07
v1.36.0-alpha.1.0.20260605181810-93779a5f617eHigh risk1492026-06-06
v0.0.0-20260605181810-93779a5f617eHigh risk1492026-06-06
v1.36.0-alpha.1.0.20260605065802-fbd3406c60d5High risk1492026-06-06
v0.0.0-20260605065802-fbd3406c60d5High risk1492026-06-06
v1.36.0-alpha.1.0.20260602144951-1782152ab6b0High risk1492026-06-03
v0.0.0-20260602144951-1782152ab6b0High risk1492026-06-03
v1.36.0-alpha.1.0.20260530180848-5449914cfbe3High risk1492026-05-31
v0.0.0-20260530180848-5449914cfbe3High risk1492026-05-31
v1.36.0-alpha.1.0.20260530143048-8a38af982000High risk1492026-05-31
v0.0.0-20260530143048-8a38af982000High risk1492026-05-31
v1.36.0-alpha.1.0.20260530060649-b1ac90ed8016Review1492026-05-31
v0.0.0-20260530060649-b1ac90ed8016Review1492026-05-31
v1.36.0-alpha.1.0.20260528103050-24864df65254High risk1492026-05-30
v0.0.0-20260528103050-24864df65254High risk1492026-05-30
v1.36.0-alpha.1.0.20260528052846-c3fab9010d33High risk1492026-05-30
v0.0.0-20260528052846-c3fab9010d33High risk1492026-05-30
v1.36.0-alpha.1.0.20260528023646-45131d973853High risk1492026-05-30
v0.0.0-20260528023646-45131d973853High risk1492026-05-30
v0.0.0-20260529160254-34c319b63a1aReview1492026-05-30
v0.0.0-20260529135251-a390d1837b78Review1492026-05-30
v1.36.0-alpha.1.0.20260529122451-5d39140b7197Review1492026-05-30
v0.0.0-20260529122451-5d39140b7197Review1492026-05-30
v0.0.0-20260528171652-4d09962af21eReview1492026-05-29
v1.35.1Review1432026-05-29

Block this in CI

PkgRadar gates k8s.io/kops (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go k8s.io/[email protected]