PkgRadar

Go modules · proxy.golang.org

github.com/microsoft/cosesign1go

Tls Verification Disabled: matched "InsecureSkipVerify: true"

Why PkgRadar flagged v1.6.0

SeveritySignalEvidence
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · github.com/microsoft/[email protected]/cmd/sign1util/ccf_keyfetch.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.6.0Review122026-06-19
v1.6.0-alpha1Low risk02026-06-16
v1.5.0Low risk02026-05-29

Block this in CI

PkgRadar gates github.com/microsoft/cosesign1go (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/microsoft/[email protected]