PkgRadar

Go modules · proxy.golang.org

github.com/apecloud/kb-cloud-client-go

Shell Credential File Read

Why PkgRadar flagged v1.0.4-0.20260623130211-746876cc33b8

SeveritySignalEvidence
highShell Credential File Readgithub.com/apecloud/[email protected]/api/kbcloud/admin/model_tls_type.go
highShell Credential File Readgithub.com/apecloud/[email protected]/api/kbcloud/model_tls_type.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.0.4-0.20260623130211-746876cc33b8High risk502026-06-25
v0.0.0-20260618154232-1a891e498849Low risk02026-06-19
v1.0.4-0.20260617121801-9af91a4080f3Low risk02026-06-18
v0.0.0-20260617121801-9af91a4080f3Low risk02026-06-18
v1.0.4-0.20260612125522-c9cf0043d5aaLow risk02026-06-16
v1.0.4-0.20260615041932-f649452b1280Low risk02026-06-16
v0.29.0-alpha.152.0.20250124051643-8e019c80383dLow risk02026-06-16
v1.0.4-0.20260615050306-d4c20ce9f7deLow risk02026-06-16
v1.0.4-0.20260509014431-474cf6255d4fLow risk02026-06-11
v1.0.4-0.20260610090437-cdf13cc17be5Low risk02026-06-11
v1.0.4-0.20260528034008-fcdee388a03cLow risk02026-06-10

Block this in CI

PkgRadar gates github.com/apecloud/kb-cloud-client-go (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/apecloud/[email protected]