PkgRadar

Go modules · proxy.golang.org

github.com/djoshy/machine-config-operator

Tls Verification Disabled: matched "InsecureSkipVerify: true"

Why PkgRadar flagged v0.0.0-20260618140350-5d90e399e718

SeveritySignalEvidence
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · github.com/djoshy/[email protected]/cmd/apiserver-watcher/run.go
mediumTls Verification Disabledmatched "verify=false" · github.com/djoshy/[email protected]/devex/cmd/mco-builder/internal/builders/common.go
mediumTls Verification Disabledmatched "verify=false" · github.com/djoshy/[email protected]/devex/cmd/mco-builder/internal/builders/podman.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260618140350-5d90e399e718Review362026-06-20
v0.0.0-20260611174504-ae65f6d89b01Low risk02026-06-13
v0.0.0-20260608192052-62dbab4477ceLow risk02026-06-10
v0.0.0-20260602183623-3ffecb58d54aLow risk02026-06-05

Block this in CI

PkgRadar gates github.com/djoshy/machine-config-operator (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/djoshy/[email protected]