PkgRadar

Go modules · proxy.golang.org

github.com/consensys/quorum

Shell Credential File Read, Go Generate Shell, Remote Payload +3 more

Why PkgRadar flagged v1.9.25-0.20260605022711-5ffacc482866

SeveritySignalEvidence
highShell Credential File Readgithub.com/consensys/[email protected]/accounts/keystore/key.go
highShell Credential File Readgithub.com/consensys/[email protected]/accounts/keystore/passphrase.go
highShell Credential File Readgithub.com/consensys/[email protected]/accounts/keystore/plain.go
highShell Credential File Readgithub.com/consensys/[email protected]/accounts/keystore/wallet.go
highShell Credential File Readgithub.com/consensys/[email protected]/mobile/accounts.go
mediumGo Generate Shellgithub.com/consensys/[email protected]/signer/fourbyte/fourbyte.go
mediumRemote Payloadgithub.com/consensys/[email protected]/build/ci.go
mediumTls Verification Disabledgithub.com/consensys/[email protected]/qlight/config.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.9.25-0.20260605022711-5ffacc482866High risk1492026-06-25

Block this in CI

PkgRadar gates github.com/consensys/quorum (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/consensys/[email protected]
github.com/consensys/quorum — Go modules security scan | PkgRadar