PkgRadar

Go modules · proxy.golang.org

sigs.k8s.io/cluster-api/hack/tools

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged v0.0.0-20260616114133-0b1e14c96d69

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · sigs.k8s.io/cluster-api/hack/[email protected]/mdbook/embed/embed.go
mediumGo Mod Replace Localgo.mod replace directive redirects to a local filesystem path — non-portable / dev-time only. · sigs.k8s.io/cluster-api/hack/[email protected]/go.mod

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260616114133-0b1e14c96d69Review222026-06-17
v0.0.0-20260616054126-d4a5c7c90b65Review222026-06-17
v0.0.0-20260615093726-7e279329b902Review222026-06-16
v0.0.0-20260612131243-aad013d6af21Review222026-06-13
v0.0.0-20250801091338-acb48e27ba28Review222026-06-13
v0.0.0-20260608175946-4e113229504cReview222026-06-09
v0.0.0-20260608115545-15f3dc16af80Review222026-06-09
v0.0.0-20260608095341-1ed10965999dReview222026-06-09
v0.0.0-20260608092440-8a917d50681cReview222026-06-09
v0.0.0-20260608053031-274bf8302711Review222026-06-09
v0.0.0-20260603103357-6843c4566787Review222026-06-04
v0.0.0-20260602163347-8d6b3ffc292eReview222026-06-03
v0.0.0-20260602160945-304e18513291Review222026-06-03
v0.0.0-20260602120346-a059f6bf0e4bReview222026-06-03
v0.0.0-20260529183250-359c22f570f0Review222026-05-30
v0.0.0-20260529141651-0186362299ffReview222026-05-30

Block this in CI

PkgRadar gates sigs.k8s.io/cluster-api/hack/tools (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go sigs.k8s.io/cluster-api/hack/[email protected]