PkgRadar

Go modules · proxy.golang.org

mygithub.libinneed.workers.dev/runatlantis/atlantis

Remote Payload: matched "github.com/open-policy-agent/conftest/releases/download"

Why PkgRadar flagged v0.44.1-0.20260612010711-ffacfba754a0

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/open-policy-agent/conftest/releases/download" · mygithub.libinneed.workers.dev/runatlantis/[email protected]/server/core/runtime/policy/conftest_client.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · mygithub.libinneed.workers.dev/runatlantis/[email protected]/server/events/vcs/azuredevops/client.go
mediumRemote Payloadmatched "api.github.com/graphql" · mygithub.libinneed.workers.dev/runatlantis/[email protected]/server/events/vcs/github/client.go
mediumRemote Payloadmatched "cURL " · mygithub.libinneed.workers.dev/runatlantis/[email protected]/testdrive/utils.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.44.1-0.20260612010711-ffacfba754a0High risk482026-06-15
v0.44.0High risk482026-06-15

Block this in CI

PkgRadar gates mygithub.libinneed.workers.dev/runatlantis/atlantis (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go mygithub.libinneed.workers.dev/runatlantis/[email protected]