PkgRadar

Go modules · proxy.golang.org

github.com/PlakarKorp/integrations/sftp

Credential file access: matched "id_rsa"

Why PkgRadar flagged v1.0.7

SeveritySignalEvidence
mediumCredential file accessmatched "id_rsa" · github.com/plakarkorp/integrations/[email protected]/common/sftp.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.1.1-rc.4Low risk02026-06-06
v1.1.1-rc.3Low risk02026-06-06
v1.1.2-0.20260605130522-f059015c417bLow risk02026-06-06
v1.1.1Low risk02026-06-06
v1.1.1-rc.2Low risk02026-06-03
v1.1.1-rc.1Low risk02026-06-03
v1.1.1-0.20260528145030-4b564a224d16Low risk02026-06-02
v1.0.7Review102026-06-02
v1.1.0-beta.5Low risk02026-06-02
v1.1.0-beta.2Low risk02026-06-02
v1.0.8Review102026-06-02

Block this in CI

PkgRadar gates github.com/PlakarKorp/integrations/sftp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/PlakarKorp/integrations/[email protected]