PkgRadar

Go modules · proxy.golang.org

github.com/cloudnative-pg/cloudnative-pg

Tls Verification Disabled: matched "InsecureSkipVerify: true"

Why PkgRadar flagged v1.30.0-rc1

SeveritySignalEvidence
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · github.com/cloudnative-pg/[email protected]/pkg/certs/tls.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.30.0-rc1Review122026-06-20
v1.28.4-0.20260611094714-d23e0d4919c4Low risk02026-06-14
v1.29.1-0.20260612232032-17311c2b135bLow risk02026-06-14
v1.28.4-0.20260605150535-8469ba5fd1caLow risk02026-06-07
v1.29.1-0.20260605150453-28eb80887e1dLow risk02026-06-07
v1.28.4-0.20260601124336-437025bc66a6Low risk02026-06-03
v1.29.1-0.20260601124253-758532a6f4bcLow risk02026-06-03

Block this in CI

PkgRadar gates github.com/cloudnative-pg/cloudnative-pg (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/cloudnative-pg/[email protected]