PkgRadar

Go modules · proxy.golang.org

github.1485827954.workers.dev/openfga/openfga

Tls Verification Disabled: matched "InsecureSkipVerify: true"

Why PkgRadar flagged v1.18.1-0.20260618204928-9a556d8a134d

SeveritySignalEvidence
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · github.1485827954.workers.dev/openfga/[email protected]/cmd/run/run.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.18.1-0.20260618204928-9a556d8a134dReview122026-06-20
v1.17.0Review122026-06-20
v1.18.1-0.20260617011126-91234a2cbbeaLow risk02026-06-19
v1.18.0Low risk02026-06-19
v1.16.1Low risk02026-06-02

Block this in CI

PkgRadar gates github.1485827954.workers.dev/openfga/openfga (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.1485827954.workers.dev/openfga/[email protected]