PkgRadar

Go modules · proxy.golang.org

github.com/mongodb/mongodb-cli/v2

Shell Credential File Read, Tls Verification Disabled

Why PkgRadar flagged v2.0.0-20260623085437-39bdf3e8f587

SeveritySignalEvidence
highShell Credential File Readgithub.com/mongodb/mongodb-cli/[email protected]/internal/decryption/encrypted_audit_log.go
highShell Credential File Readgithub.com/mongodb/mongodb-cli/[email protected]/internal/decryption/keyproviders/key_provider.go
mediumTls Verification Disabledgithub.com/mongodb/mongodb-cli/[email protected]/internal/store/store.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v2.0.0-20260623085437-39bdf3e8f587High risk1022026-06-25
v2.0.0-20260609031007-191214c6ca71Low risk02026-06-11
v2.0.0-20260526080929-4a3115cf6ad5Low risk02026-05-30

Block this in CI

PkgRadar gates github.com/mongodb/mongodb-cli/v2 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/mongodb/mongodb-cli/[email protected]