PkgRadar

Go modules · proxy.golang.org

github.com/bitechdev/ResolveSpec

Shell Credential File Read, Obfuscation Density

Why PkgRadar flagged v1.1.12

SeveritySignalEvidence
highShell Credential File Readgithub.com/bitechdev/[email protected]/pkg/security/keystore.go
highShell Credential File Readgithub.com/bitechdev/[email protected]/pkg/security/keystore_authenticator.go
highShell Credential File Readgithub.com/bitechdev/[email protected]/pkg/security/keystore_config.go
highShell Credential File Readgithub.com/bitechdev/[email protected]/pkg/security/keystore_database.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.1.12High risk1002026-06-23
v1.1.11-0.20260608131358-c120b49529f9Low risk02026-06-09
v1.1.10Low risk02026-06-09
v1.1.10-0.20260607171359-29449c93d58dLow risk02026-06-09
v1.1.9Low risk02026-06-09
v1.1.8Low risk02026-06-06
v1.1.6Low risk02026-06-05

Block this in CI

PkgRadar gates github.com/bitechdev/ResolveSpec (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/bitechdev/[email protected]