PkgRadar

Go modules · proxy.golang.org

github.com/AthenZ/athenz

Shell Credential File Read, Obfuscation Density

Why PkgRadar flagged v1.12.44-0.20260624035623-3a7ae0530aa5

SeveritySignalEvidence
highShell Credential File Readgithub.com/athenz/[email protected]/libs/go/zmssvctoken/keystore.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.12.44-0.20260624035623-3a7ae0530aa5High risk452026-06-26
v1.12.44-0.20260619152821-0afddc9c6af7Low risk02026-06-20
v1.12.43Low risk02026-06-20
v1.12.43-0.20260618012012-5c5421270ce5Low risk02026-06-19
v1.12.43-0.20260602175023-3aefdf17f7dbLow risk02026-06-05
v1.12.38-0.20260409205040-51fda18727a2Low risk02026-06-05
v1.12.43-0.20260602050927-1c234e361ef9Low risk02026-06-03
v1.12.43-0.20260528063514-7f32fa5f302fLow risk02026-05-30
v1.12.42Low risk02026-05-30
v1.12.43-0.20260528063957-fed5efe72c77Low risk02026-05-30

Block this in CI

PkgRadar gates github.com/AthenZ/athenz (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/AthenZ/[email protected]