PkgRadar

Go modules · proxy.golang.org

github.com/TrioloItamar/avalanchego

Shell Credential File Read, Remote Payload, Tls Verification Disabled

Why PkgRadar flagged v1.10.9

SeveritySignalEvidence
highShell Credential File Read
highShell Credential File Read
highShell Credential File Read
mediumRemote Payload
mediumTls Verification Disabled

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.10.9High risk1192026-06-27
v1.10.16-0.20231113210902-c3750f372127High risk1192026-06-27
v1.10.16-0.20231117202622-40934bb50220High risk1192026-06-27
v1.10.1-0.20230414110926-9078977b770dHigh risk1072026-06-27
v1.4.7High risk1072026-06-27
v1.10.15High risk1192026-06-27

Block this in CI

PkgRadar gates github.com/TrioloItamar/avalanchego (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/TrioloItamar/[email protected]
github.com/TrioloItamar/avalanchego — Go modules security scan | PkgRadar