PkgRadar

Go modules · proxy.golang.org

github.com/ldez/golangci-lint/v2

Tls Verification Disabled: matched "verify = false"

Why PkgRadar flagged v2.0.0-20260616203855-9e89eac4f50c

SeveritySignalEvidence
mediumTls Verification Disabledmatched "verify = false" · github.com/ldez/golangci-lint/[email protected]/internal/go/cache/cache.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v2.0.0-20260616203855-9e89eac4f50cReview122026-06-20
v2.0.0-20260609204839-c1d8288e1543Low risk02026-06-14
v2.0.0-20260608105353-9c5ec8122806Low risk02026-06-09
v2.0.0-20260604211744-8baaf6d0eacfLow risk02026-06-07
v2.0.0-20260602121433-9ca139974062Low risk02026-06-04
v2.0.0-20260531140520-3c81e8635937Low risk02026-06-02
v2.0.0-20260527013714-2bff0e3f1cc5Low risk02026-05-30

Block this in CI

PkgRadar gates github.com/ldez/golangci-lint/v2 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/ldez/golangci-lint/[email protected]