PkgRadar

Go modules · proxy.golang.org

github.com/crypto-org-chain/cronos

Shell Credential File Read, Obfuscation Density

Why PkgRadar flagged v1.7.1-0.20260622181647-b100a8bafc8f

SeveritySignalEvidence
highShell Credential File Readgithub.com/crypto-org-chain/[email protected]/x/e2ee/keyring/keyring.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.7.1-0.20260622181647-b100a8bafc8fHigh risk452026-06-24
v1.7.8High risk452026-06-24
v1.7.1-0.20260609041038-4cd2b9219a97Low risk02026-06-11
v1.7.7Low risk02026-06-11

Block this in CI

PkgRadar gates github.com/crypto-org-chain/cronos (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/crypto-org-chain/[email protected]