PkgRadar

Go modules · proxy.golang.org

github.com/open-edge-platform/os-image-composer

Tls Verification Disabled

Why PkgRadar flagged v0.0.0-20260619135705-12c4cdcd634d

SeveritySignalEvidence
mediumTls Verification Disabledgithub.com/open-edge-platform/[email protected]/internal/utils/network/download.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260619135705-12c4cdcd634dReview122026-06-22
v0.0.0-20260618022803-c9cc2683f619Low risk02026-06-19
v0.0.0-20260616091125-50aab90adea0Low risk02026-06-18
v0.0.0-20260612174218-f865162a1452Low risk02026-06-14
v0.0.0-20260611133425-0e7129206e71Low risk02026-06-12
v0.0.0-20260610151155-18e1c2749bc6Low risk02026-06-11
v0.0.0-20260529023059-0cc1d791710aLow risk02026-06-01
v0.0.0-20260528042454-d8f976023bceLow risk02026-05-29

Block this in CI

PkgRadar gates github.com/open-edge-platform/os-image-composer (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/open-edge-platform/[email protected]