PkgRadar

Go modules · proxy.golang.org

github.com/elixir-no/fega-norway/cli/lega-commander

Tls Verification Disabled: matched "InsecureSkipVerify: true"

Why PkgRadar flagged v0.0.0-20260619110403-25be51fe91ad

SeveritySignalEvidence
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · github.com/elixir-no/fega-norway/cli/[email protected]/requests/requests.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260619110403-25be51fe91adReview122026-06-20
v0.0.0-20260618085928-64a03b19ab30Low risk02026-06-19
v0.0.0-20260617102843-1e6bfc8f0b7eLow risk02026-06-19
v0.0.0-20260615122911-07296f49ee5bLow risk02026-06-16
v0.0.0-20260603101312-e6c53fc61abfLow risk02026-06-06
v0.0.0-20260529102223-634929d9a5ccLow risk02026-06-01
v0.0.0-20260527073319-b20080df1f77Low risk02026-05-29

Block this in CI

PkgRadar gates github.com/elixir-no/fega-norway/cli/lega-commander (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/elixir-no/fega-norway/cli/[email protected]