PkgRadar

Go modules · proxy.golang.org

github.com/markphelps/flipt/build

Remote Payload, Tls Verification Disabled, Credential file access

Why PkgRadar flagged v0.0.0-20260624154542-989217a12ba6

SeveritySignalEvidence
mediumRemote Payloadgithub.com/markphelps/flipt/[email protected]/testing/cli.go
mediumTls Verification Disabledgithub.com/markphelps/flipt/[email protected]/testing/integration.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260624154542-989217a12ba6Review392026-06-26
v0.0.0-20260623184049-5892c8f3f318Low risk02026-06-26

Block this in CI

PkgRadar gates github.com/markphelps/flipt/build (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/markphelps/flipt/[email protected]