PkgRadar

Go modules · proxy.golang.org

github.com/block/spirit

Tls Verification Disabled

Why PkgRadar flagged v0.15.2-0.20260620184601-ad03d2d9c0de

SeveritySignalEvidence
mediumTls Verification Disabledgithub.com/block/[email protected]/pkg/dbconn/conn.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.15.2-0.20260620184601-ad03d2d9c0deReview122026-06-21
v0.15.1Review122026-06-21
v0.15.1-0.20260617235652-98a38a253173Low risk02026-06-18
v0.15.0Low risk02026-06-18
v0.14.1-0.20260615145125-51dae11bf5d0Low risk02026-06-16
v0.14.1-0.20260614225444-dd871a952a9fLow risk02026-06-15
v0.14.1-0.20260614224649-b3d22f26a4bcLow risk02026-06-15
v0.14.1-0.20260612175700-606ef31db10eLow risk02026-06-13
v0.14.1-0.20260612155839-590c481e0cebLow risk02026-06-13
v0.14.1-0.20260612140803-de986e9f6cbbLow risk02026-06-13
v0.14.1-0.20260612020740-55e5b7fe5df4Low risk02026-06-13
v0.14.1-0.20260611143815-b4af7d963a9eLow risk02026-06-12
v0.14.1-0.20260610023522-b527b629ad28Low risk02026-06-11
v0.14.1-0.20260610005732-4bea953745e4Low risk02026-06-11
v0.14.1-0.20260605142839-c9a258341463Low risk02026-06-10
v0.14.1-0.20260601195732-86c57e3e1d73Low risk02026-06-02
v0.14.1-0.20260601153425-5abdd874d114Low risk02026-06-02
v0.14.1-0.20260531232845-4141c8a2c690Low risk02026-06-02
v0.14.1-0.20260528150947-ab3e82474753Low risk02026-05-29

Block this in CI

PkgRadar gates github.com/block/spirit (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/block/[email protected]