PkgRadar

Go modules · proxy.golang.org

cnb.cool/15m/kiwi

Tls Verification Disabled: matched "InsecureSkipVerify: true"

Why PkgRadar flagged v0.0.0-20260619194303-97cb09da9309

SeveritySignalEvidence
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · cnb.cool/15m/[email protected]/registry_profile.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260619194303-97cb09da9309Review122026-06-20
v0.0.0-20260619192645-b82c6aaff8ceReview122026-06-20
v0.0.0-20260616185831-1e9a1b1eeb48Low risk02026-06-17
v0.0.0-20260616163421-e4626cecfe17Low risk02026-06-17
v0.0.0-20260615101043-7e87be90e26fLow risk02026-06-16
v0.0.0-20260615084718-f26c95f59374Low risk02026-06-16
v0.0.0-20260615082116-a7bdaaa90c49Low risk02026-06-16
v0.0.0-20260608213932-3941df54d1d7Low risk02026-06-09
v0.0.0-20260528181929-be70a4f6faa8Low risk02026-06-08
v0.0.0-20260607175017-920380ec04b1Low risk02026-06-08
v0.0.0-20260604180724-16db74fe3c3bLow risk02026-06-06

Block this in CI

PkgRadar gates cnb.cool/15m/kiwi (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go cnb.cool/15m/[email protected]