PkgRadar

Go modules · proxy.golang.org

github.com/gRPC/grpc-go

Tls Verification Disabled: matched "InsecureSkipVerify: true"

Why PkgRadar flagged v1.83.0-dev.0.20260612120310-5c7f93679ec9

SeveritySignalEvidence
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · github.com/grpc/[email protected]/internal/credentials/xds/handshake_info.go
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · github.com/grpc/[email protected]/internal/xds/bootstrap/tlscreds/bundle.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.83.0-dev.0.20260612120310-5c7f93679ec9Review242026-06-20
v0.0.0-20260612120310-5c7f93679ec9Review242026-06-20
v1.83.0-dev.0.20260609194428-f1864955bbb4Low risk02026-06-11
v1.83.0-devLow risk02026-06-11
v1.82.0-dev.0.20260603173933-91dd64f4b83cLow risk02026-06-04

Block this in CI

PkgRadar gates github.com/gRPC/grpc-go (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/gRPC/[email protected]