PkgRadar

Go modules · proxy.golang.org

github.com/h0rn3t/gitlab-mcp-server/v2

Tls Verification Disabled: matched "InsecureSkipVerify: true"

Why PkgRadar flagged v2.0.0-20260616114257-c7056d77fb22

SeveritySignalEvidence
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · github.com/h0rn3t/gitlab-mcp-server/[email protected]/internal/gitlab/client.go
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · github.com/h0rn3t/gitlab-mcp-server/[email protected]/internal/oauth/verifier.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v2.0.0-20260616114257-c7056d77fb22Review242026-06-20
v2.0.0-20260608185839-f864a7ae15d3Low risk02026-06-12
v2.0.0-20260608083300-7403effab470Low risk02026-06-09

Block this in CI

PkgRadar gates github.com/h0rn3t/gitlab-mcp-server/v2 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/h0rn3t/gitlab-mcp-server/[email protected]