PkgRadar

Go modules · proxy.golang.org

github.com/go-gitea/Gitea

Remote Payload, Tls Verification Disabled, Credential file access +2 more

Why PkgRadar flagged v1.27.0-dev.0.20260624211313-2e1be0b11442

SeveritySignalEvidence
mediumRemote Payloadgithub.com/go-gitea/[email protected]/build/generate-emoji.go
mediumTls Verification Disabledgithub.com/go-gitea/[email protected]/modules/private/internal.go
mediumTls Verification Disabledgithub.com/go-gitea/[email protected]/routers/web/goget.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.27.0-dev.0.20260624211313-2e1be0b11442Review982026-06-25
v1.26.3Review922026-06-25
v1.26.4Review922026-06-25

Block this in CI

PkgRadar gates github.com/go-gitea/Gitea (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/go-gitea/[email protected]