PkgRadar

Go modules · proxy.golang.org

git.apache.org/thrift.git

Tls Verification Disabled, Obfuscation Density

Why PkgRadar flagged v0.23.1-0.20260618225216-137d693e281d

SeveritySignalEvidence
mediumTls Verification Disabledgit.apache.org/[email protected]/tutorial/go/src/main.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.23.1-0.20260618225216-137d693e281dReview122026-06-22
v0.0.0-20260618225216-137d693e281dReview122026-06-22
v0.0.0-20260617235253-c016cd23c8bdLow risk02026-06-19
v0.23.1-0.20260617235253-c016cd23c8bdLow risk02026-06-18
v0.0.0-20260617212609-0e4a47eac957Low risk02026-06-18
v0.23.1-0.20260617201850-7d1c098df544Low risk02026-06-18
v0.23.1-0.20260613095333-983c813c9a1aLow risk02026-06-14
v0.0.0-20260613095333-983c813c9a1aLow risk02026-06-14
v0.0.0-20260611205715-35c1a53dd6deLow risk02026-06-12
v0.23.1-0.20260609215047-445c062e3ac7Low risk02026-06-11
v0.23.1-0.20260606163542-73a168bed349Low risk02026-06-08
v0.0.0-20260606163542-73a168bed349Low risk02026-06-08
v0.23.1-0.20260603211227-208b779bc98cLow risk02026-06-06
v0.0.0-20260603211227-208b779bc98cLow risk02026-06-06
v0.23.1-0.20260603002616-318212b93859Low risk02026-06-04
v0.0.0-20260603002616-318212b93859Low risk02026-06-04
v0.23.1-0.20260530222330-5e29f31685b6Low risk02026-06-01
v0.0.0-20260530222330-5e29f31685b6Low risk02026-06-01
v0.23.1-0.20260529002519-1ffdcf24e4abLow risk02026-05-30
v0.0.0-20260529002519-1ffdcf24e4abLow risk02026-05-30

Block this in CI

PkgRadar gates git.apache.org/thrift.git (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go git.apache.org/[email protected]