PkgRadar

Go modules · proxy.golang.org

github.com/baditaflorin/go-common

Shell Credential File Read

Why PkgRadar flagged v0.67.0

SeveritySignalEvidence
highShell Credential File Readgithub.com/baditaflorin/[email protected]/middleware/auth_keystore.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.67.0High risk452026-06-24
v0.65.0Low risk02026-06-09
v0.63.1-0.20260608072752-22354fbc6ff1Low risk02026-06-09
v0.63.0Low risk02026-06-09
v0.62.0Low risk02026-06-08
v0.60.1-0.20260604181831-5456a09839ceLow risk02026-06-05
v0.53.0Low risk02026-06-05
v0.60.0Low risk02026-06-05
v0.59.0Low risk02026-06-05
v0.58.0Low risk02026-06-05
v0.57.0Low risk02026-06-05
v0.56.0Low risk02026-06-05
v0.55.0Low risk02026-06-05
v0.54.0Low risk02026-06-05
v0.52.0Low risk02026-06-05
v0.51.0Low risk02026-06-05
v0.50.0Low risk02026-06-05
v0.49.0Low risk02026-06-05
v0.48.0Low risk02026-06-05
v0.47.2Low risk02026-06-05
v0.47.2-0.20260604082400-2c4fb74bffa4Low risk02026-06-05
v0.47.1Low risk02026-06-05
v0.47.0Low risk02026-06-05
v0.46.0Low risk02026-06-02
v0.45.0Low risk02026-06-02
v0.44.0Low risk02026-06-02
v0.43.0Low risk02026-06-01
v0.42.0Low risk02026-06-01

Block this in CI

PkgRadar gates github.com/baditaflorin/go-common (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/baditaflorin/[email protected]