PkgRadar

Go modules · proxy.golang.org

github.com/ocfl-archive/gocfl/v2

Tls Verification Disabled: matched "InsecureSkipVerify: true"

Why PkgRadar flagged v2.0.0-20251230173141-10a640aa415b

SeveritySignalEvidence
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · github.com/ocfl-archive/gocfl/[email protected]/pkg/extension/NNNN-indexer.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v2.0.0-20251230173141-10a640aa415bReview122026-06-20
v2.0.0-20260323161011-a86dd7eeb085Low risk02026-06-14
v2.0.0-20260314132317-a6560cf2e709Low risk02026-06-14
v2.0.0-20260310151124-2f160979b677Low risk02026-06-14
v2.0.0-20260228172401-76a26cb26ab7Low risk02026-06-14
v2.0.0-20260401070237-93f5a9a5fd05Low risk02026-06-14
v2.0.0-20251226172251-de71a2b6e0e5Low risk02026-06-14

Block this in CI

PkgRadar gates github.com/ocfl-archive/gocfl/v2 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/ocfl-archive/gocfl/[email protected]