PkgRadar

Go modules · proxy.golang.org

k8s.io/perf-tests

Remote Payload: matched "wget "

Why PkgRadar flagged v0.0.0-20260528084052-7c00b2b0ee98

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · k8s.io/[email protected]/golang/build-go.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260611182259-56c278798385Low risk02026-06-12
v0.0.0-20260611115251-dcc759436182Low risk02026-06-12
v0.0.0-20260610194656-c0b947af9df3Low risk02026-06-11
v0.0.0-20260609141751-2f1bca953fc0Low risk02026-06-10
v0.0.0-20260608204745-4c65f154710fLow risk02026-06-09
v0.0.0-20260608174751-6727c00501f3Low risk02026-06-09
v0.0.0-20260608164548-9f98015e952dLow risk02026-06-09
v0.0.0-20260608085649-4fee76ce8d38Low risk02026-06-09
v0.0.0-20260608073837-0c76bf46e74cLow risk02026-06-09
v0.0.0-20260605133810-8a76880121c7Low risk02026-06-06
v0.0.0-20260604220758-b29ed84ea02cLow risk02026-06-06
v0.0.0-20260603181152-cd6a929cab8eLow risk02026-06-04
v0.0.0-20260603125547-9d532cebfb96Low risk02026-06-04
v0.0.0-20260528125850-7c74f74a31e5Low risk02026-05-29
v0.0.0-20260528084052-7c00b2b0ee98Review172026-05-29

Block this in CI

PkgRadar gates k8s.io/perf-tests (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go k8s.io/[email protected]