PkgRadar

Go modules · proxy.golang.org

github.com/google/go-containerRegistry

Remote Payload, Tls Verification Disabled

Why PkgRadar flagged v0.20.6

SeveritySignalEvidence
mediumRemote Payloadgithub.com/google/[email protected]/cmd/crane/cmd/auth.go
mediumTls Verification Disabledgithub.com/google/[email protected]/pkg/crane/options.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.20.6Review242026-06-21
v0.21.6Review242026-06-21
v0.18.0Review242026-06-21
v0.21.0Review242026-06-21
v0.19.1Review242026-06-21
v0.20.4Review242026-06-21
v0.12.0Low risk02026-06-21
v0.20.5Review242026-06-21
v0.21.5Review242026-06-21
v0.1.2Low risk02026-06-21
v0.1.3Low risk02026-06-21
v0.9.0Review122026-06-21
v0.3.0Low risk02026-06-21
v0.21.4Review242026-06-21
v0.15.0Review122026-06-21
v0.4.0Low risk02026-06-21
v0.20.2Review242026-06-21
v0.20.1Review242026-06-21
v0.4.1Low risk02026-06-21
v0.1.4Low risk02026-06-21
v0.21.1Review242026-06-21
v0.21.2Review242026-06-21
v0.20.0Review242026-06-21
v0.5.1Low risk02026-06-21
v0.6.1Low risk02026-06-21
v0.8.0Low risk02026-06-21
v0.5.0Low risk02026-06-21
v0.6.0Low risk02026-06-21
v0.7.0Low risk02026-06-21
v0.14.0Review122026-06-21
v0.12.1Low risk02026-06-21
v0.11.0Review122026-06-21

Block this in CI

PkgRadar gates github.com/google/go-containerRegistry (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/google/[email protected]