PkgRadar

Go modules · proxy.golang.org

github.com/openshift/machine-config-operator

Tls Verification Disabled: matched "InsecureSkipVerify: true"

Why PkgRadar flagged v0.0.1-0.20260618233935-feeae4ab4200

SeveritySignalEvidence
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · github.com/openshift/[email protected]/cmd/apiserver-watcher/run.go
mediumTls Verification Disabledmatched "verify=false" · github.com/openshift/[email protected]/devex/cmd/mco-builder/internal/builders/common.go
mediumTls Verification Disabledmatched "verify=false" · github.com/openshift/[email protected]/devex/cmd/mco-builder/internal/builders/podman.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.1-0.20260618233935-feeae4ab4200Review362026-06-20
v4.0.0-alpha.0.0.20200121012050-f56d736e74af+incompatibleReview102026-06-20
v0.0.1-0.20260617051815-d0c3a5e8ca12Low risk02026-06-19
v0.0.1-0.20260610135854-929572e3aa4fLow risk02026-06-19
v0.0.1-0.20260613123141-6a2c5c65419cLow risk02026-06-16
v0.0.1-0.20250131190019-4c9d2f8cc0b6Low risk02026-06-10
v0.0.1-0.20260609111321-1e2bb8be4c46Low risk02026-06-10
v0.0.1-0.20260608101403-4412c7c6abf7Low risk02026-06-09
v0.0.1-0.20260605214237-62b06d28399bLow risk02026-06-07
v0.0.1-0.20260605162018-a250b82705e3Low risk02026-06-07
v0.0.1-0.20260605031204-dc8e49646d47Low risk02026-06-06
v0.0.1-0.20260603160333-08af7a3d3d94Low risk02026-06-06
v0.0.1-0.20260604232919-5d88e8db58aeLow risk02026-06-05
v0.0.1-0.20260603201943-1bee530c4d08Low risk02026-06-05
v0.0.1-0.20260604173448-218530d8088fLow risk02026-06-05
v0.0.0-20260604125821-2a19fa0e6412Low risk02026-06-05
v0.0.1-0.20260604141550-544f39019969Low risk02026-06-05
v0.0.1-0.20260604125821-2a19fa0e6412Low risk02026-06-05
v0.0.1-0.20260602024944-09ddec72f4ebLow risk02026-06-03
v0.0.1-0.20250416211524-b38a182b1788Low risk02026-06-02
v0.0.0-20260528175540-7217c9a97f91Low risk02026-06-01
v0.0.0-20260528204828-d72b715f8f9eLow risk02026-06-01
v0.0.1-0.20260526215811-e50d6556bf00Low risk02026-05-31
v0.0.1-0.20260528091046-2ec93215890fLow risk02026-05-30
v0.0.0-20260527211152-6cee7bf03436Low risk02026-05-30
v0.0.1-0.20260520065934-577d3ad97fb1Low risk02026-05-30
v0.0.1-0.20260528204828-d72b715f8f9eLow risk02026-05-30

Block this in CI

PkgRadar gates github.com/openshift/machine-config-operator (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/openshift/[email protected]