PkgRadar

Go modules · proxy.golang.org

github.com/infinitbyte/framework

Shell Credential File Read, Tls Verification Disabled, Remote Payload +1 more

Why PkgRadar flagged v1.4.2

SeveritySignalEvidence
highShell Credential File Readgithub.com/infinitbyte/[email protected]/lib/keystore/file_keystore.go
highShell Credential File Readgithub.com/infinitbyte/[email protected]/lib/keystore/keystore.go
highShell Credential File Readgithub.com/infinitbyte/[email protected]/modules/keystore/keystore.go
mediumTls Verification Disabledgithub.com/infinitbyte/[email protected]/core/api/client.go
mediumTls Verification Disabledgithub.com/infinitbyte/[email protected]/core/elastic/domain_actions.go
mediumTls Verification Disabledgithub.com/infinitbyte/[email protected]/core/env/http_client.go
mediumTls Verification Disabledgithub.com/infinitbyte/[email protected]/core/util/webhunter.go
mediumRemote Payloadgithub.com/infinitbyte/[email protected]/lib/guardian/_examples/kubernetes/mock.go
mediumTls Verification Disabledgithub.com/infinitbyte/[email protected]/plugins/replay/replay.go
mediumTls Verification Disabledgithub.com/infinitbyte/[email protected]/plugins/smtp/smtp.go
mediumGo Mod Replace Localgithub.com/infinitbyte/[email protected]/go.mod

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.4.2High risk1672026-06-24

Block this in CI

PkgRadar gates github.com/infinitbyte/framework (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/infinitbyte/[email protected]