Go modules · proxy.golang.org
github.com/Smallstep/certificates
Shell Credential File Read, Tls Verification Disabled, Credential file access
Why PkgRadar flagged v0.14.0
| Severity | Signal | Evidence |
|---|---|---|
| high | Shell Credential File Read | github.com/smallstep/[email protected]/authority/provisioner/keystore.go |
| medium | Tls Verification Disabled | github.com/smallstep/[email protected]/acme/challenge.go |
| medium | Tls Verification Disabled | github.com/smallstep/[email protected]/ca/client.go |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v0.14.0 | High risk | 74 | 2026-06-25 |
v0.14.1 | High risk | 74 | 2026-06-25 |
v0.14.2 | High risk | 74 | 2026-06-25 |
v0.14.3 | High risk | 74 | 2026-06-25 |
v0.14.4 | High risk | 74 | 2026-06-25 |
v0.14.5 | High risk | 74 | 2026-06-25 |
v0.14.6 | High risk | 74 | 2026-06-25 |
v0.15.0 | High risk | 74 | 2026-06-25 |
v0.15.1 | High risk | 74 | 2026-06-25 |
v0.15.2 | High risk | 74 | 2026-06-25 |
v0.15.3 | High risk | 74 | 2026-06-25 |
v0.15.4 | High risk | 74 | 2026-06-25 |
v0.15.5 | High risk | 74 | 2026-06-25 |
v0.15.6 | High risk | 74 | 2026-06-25 |
v0.15.7 | High risk | 74 | 2026-06-25 |
v0.15.8 | High risk | 74 | 2026-06-25 |
v0.28.1 | High risk | 110 | 2026-06-25 |
v0.15.9 | High risk | 74 | 2026-06-25 |
v0.28.2 | High risk | 110 | 2026-06-25 |
v0.15.10 | High risk | 74 | 2026-06-25 |
v0.28.3 | High risk | 110 | 2026-06-25 |
v0.15.11 | High risk | 74 | 2026-06-25 |
v0.28.4 | High risk | 110 | 2026-06-25 |
v0.30.1 | High risk | 110 | 2026-06-25 |
v0.15.12 | High risk | 74 | 2026-06-25 |
v0.29.0 | High risk | 110 | 2026-06-25 |
v0.30.3-0.20260624125458-af6ef0cd105e | High risk | 110 | 2026-06-25 |
v0.30.2 | High risk | 110 | 2026-06-25 |
v0.15.13 | High risk | 74 | 2026-06-25 |
v0.30.0 | High risk | 110 | 2026-06-25 |
Block this in CI
pkgradar gate --ecosystem go github.com/Smallstep/[email protected]