# go.uber.org/zap@v1.28.0 — Threat Briefing Low risk — threat briefing for go package go.uber.org/zap@v1.28.0. Capabilities, risk paths, and what to check. - **Ecosystem:** go - **Latest version:** v1.28.0 ## Risk - **Level:** low - **Summary:** No risky changes detected ## Capability Summary | Capability | Level | |---|---| | install scripts | none | | network access | client | | filesystem | write | | shell execution | none | ## Capabilities ### Execution - CLI binary installation (Go module) [common] ### Other - Legacy Go dependency manager metadata present [common] - Code execution at module-load time (Go init) [common] - Filesystem write to temp directory [common] - GitHub Actions workflow [common] - External vendor / cloud integration [common] ### Environment - Environment variable access [common] ### Filesystem - Filesystem write [common] ### Network - Network client [common] ## Trust Signals ### Code Safety - No obfuscated or encoded payloads - No dynamic code execution - No access to sensitive paths - No network activity during install ## Maintainer