PkgRadar

Go modules · proxy.golang.org

github.com/go-acme/lego/v4

Tls Verification Disabled: matched "InsecureSkipVerify: true"

Why PkgRadar flagged v4.9.2-0.20230210090635-9b0c869f84ca

SeveritySignalEvidence
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · github.com/go-acme/lego/[email protected]/providers/dns/dnsmadeeasy/dnsmadeeasy.go
mediumRemote Payloadmatched "cURL " · github.com/go-acme/lego/[email protected]/providers/dns/rackspace/client.go
mediumRemote Payloadmatched "cURL\n\t\t\t" · github.com/go-acme/lego/[email protected]/providers/dns/rackspace/rackspace.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v4.9.2-0.20230210090635-9b0c869f84caReview412026-06-20

Block this in CI

PkgRadar gates github.com/go-acme/lego/v4 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/go-acme/lego/[email protected]