PkgRadar

Go modules · proxy.golang.org

github.com/mongodb/mongodb-atlas-cli

Shell Credential File Read, Tls Verification Disabled

Why PkgRadar flagged v0.0.0-20220913073522-be4ee0751178

SeveritySignalEvidence
highShell Credential File Readgithub.com/mongodb/[email protected]/internal/decryption/encrypted_audit_log.go
highShell Credential File Readgithub.com/mongodb/[email protected]/internal/decryption/keyproviders/key_provider.go
mediumTls Verification Disabledgithub.com/mongodb/[email protected]/internal/store/store.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20220913073522-be4ee0751178High risk1022026-06-25
v0.0.0-20220913073550-9ef822de3c69High risk1022026-06-25
v0.0.0-20220913073617-2d4ef56faa61High risk1022026-06-25
v0.0.0-20220916134854-b3e9e3634850High risk1022026-06-25
v0.0.0-20220916142331-ccdb6003006fHigh risk1022026-06-25
v0.0.0-20220916142354-79ab4973c3ceHigh risk1022026-06-25
v0.0.0-20220919102401-bdb55613baf6High risk1022026-06-25
v0.0.0-20220919122337-7674ba1eea5aHigh risk1022026-06-25
v0.0.0-20220919152315-ef75c62d6635High risk1022026-06-25
v0.0.0-20220919132227-9ab36e25b4a1High risk1022026-06-25
v0.0.0-20220920064813-e4daf120163fHigh risk1022026-06-25
v0.0.0-20220920064930-b88963599dcdHigh risk1022026-06-25
v0.0.0-20220920064838-9c0f938836c4High risk1022026-06-25
v0.0.0-20220920064903-b2dfa0544ddbHigh risk1022026-06-25
v0.0.0-20220920131924-774acf5e0575High risk1022026-06-25
v0.0.0-20220926101841-6d33b7cd2cceHigh risk1022026-06-25
v0.0.0-20220926130112-6808c4afe982High risk1022026-06-25
v0.0.0-20220926153104-49cc087627d3High risk1022026-06-25
v0.0.0-20220926175443-659a8d64b5c4High risk1022026-06-25
v0.0.0-20220927072719-ecd30257c602High risk1022026-06-25
v0.0.0-20220927072659-a3781a292bb5High risk1022026-06-25
v0.0.0-20220927072740-28652e1fdc21High risk1022026-06-25
v0.0.0-20220927072802-e8d70f9a9979High risk1022026-06-25
v0.0.0-20220927103655-5ada6c90ab9cHigh risk1022026-06-25
v0.0.0-20260623173014-ba2ba244eedfHigh risk902026-06-25
v1.22.1-0.20260623173014-ba2ba244eedfHigh risk902026-06-25
v1.22.1-0.20260611152702-22f369cf2709Low risk02026-06-16

Block this in CI

PkgRadar gates github.com/mongodb/mongodb-atlas-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/mongodb/[email protected]