PkgRadar

Go modules · proxy.golang.org

github.com/edgelesssys/contrast

Tls Verification Disabled: matched "InsecureSkipVerify: true"

Why PkgRadar flagged v1.21.1-0.20260619074257-a0b5c05aeb6c

SeveritySignalEvidence
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · github.com/edgelesssys/[email protected]/internal/atls/atls.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.21.1-0.20260619074257-a0b5c05aeb6cReview122026-06-20
v1.21.1-0.20260618135858-c36bb9335fe1Low risk02026-06-19
v0.0.0-20260618135858-c36bb9335fe1Low risk02026-06-19
v1.21.1-0.20260618093818-5a9ad151d3e8Low risk02026-06-19
v0.0.0-20260618093818-5a9ad151d3e8Low risk02026-06-19
v1.21.1-0.20260617092338-80579f99dd59Low risk02026-06-18
v1.21.1-0.20260616125546-ec83a26ac822Low risk02026-06-17
v0.0.0-20260616125546-ec83a26ac822Low risk02026-06-17
v1.21.1-0.20260615125729-3c61e1a1282dLow risk02026-06-16
v1.21.1-0.20260615110632-35f2a5b2be94Low risk02026-06-16
v0.0.0-20260615110632-35f2a5b2be94Low risk02026-06-16
v1.21.1-0.20260615051213-7b53c2d612f7Low risk02026-06-16
v0.0.0-20260615051213-7b53c2d612f7Low risk02026-06-16
v0.0.0-20260611154931-6615d9a567c3Low risk02026-06-12
v0.0.0-20260611153545-d5e59c9ccb07Low risk02026-06-12
v0.0.0-20260611151550-f721eb6fbd00Low risk02026-06-12
v1.21.1-0.20260610081717-67aa9f91bdefLow risk02026-06-11
v0.0.0-20260610081717-67aa9f91bdefLow risk02026-06-11
v1.21.1-0.20260609114029-8b2bfad01892Low risk02026-06-10
v1.21.1-0.20260608151143-25c0a7169a9aLow risk02026-06-09
v0.0.0-20260608151143-25c0a7169a9aLow risk02026-06-09
v1.21.1-0.20260608095915-cc3d34b1a2e7Low risk02026-06-09
v0.0.0-20260608095915-cc3d34b1a2e7Low risk02026-06-09
v1.21.1-0.20260608045208-0a13b4540c42Low risk02026-06-09
v0.0.0-20260608045208-0a13b4540c42Low risk02026-06-09
v0.0.0-20260603120623-406094d88986Low risk02026-06-04
v1.21.1-0.20260603090000-5b625e1917f8Low risk02026-06-04
v0.0.0-20260603090000-5b625e1917f8Low risk02026-06-04
v1.21.1-0.20260602120004-f99be92aa64fLow risk02026-06-03
v0.0.0-20260602120004-f99be92aa64fLow risk02026-06-03
v1.21.1-0.20260601115743-ca66f807b480Low risk02026-06-02
v1.21.1-0.20260601053317-c41978592d70Low risk02026-06-02
v0.0.0-20260601053317-c41978592d70Low risk02026-06-02
v1.21.1-0.20260529072545-959ddb9a345cLow risk02026-05-30
v0.0.0-20260529072545-959ddb9a345cLow risk02026-05-30
v1.21.1-0.20260528135839-006ce363736dLow risk02026-05-29
v0.0.0-20260528135839-006ce363736dLow risk02026-05-29

Block this in CI

PkgRadar gates github.com/edgelesssys/contrast (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/edgelesssys/[email protected]