PkgRadar

Go modules · proxy.golang.org

github.com/opentdf/platform/service

Tls Verification Disabled: matched "InsecureSkipVerify: true"

Why PkgRadar flagged v0.17.1-0.20260619152721-6f1e086c0fe8

SeveritySignalEvidence
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · github.com/opentdf/platform/[email protected]/pkg/server/start.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.17.1-0.20260619152721-6f1e086c0fe8Review122026-06-20
v0.15.1-0.20260619151256-20485dc6e016Review122026-06-20
v0.17.0Low risk02026-06-12
v0.16.1-0.20260610203325-9d16f8062e61Low risk02026-06-12
v0.15.1-0.20260611040432-9301867f4a93Low risk02026-06-12
v0.16.1-0.20260609225529-12d1ee6ca487Low risk02026-06-10
v0.16.1-0.20260609215606-4d1b12a63a49Low risk02026-06-10
v0.16.1-0.20260609214142-76549caca930Low risk02026-06-10
v0.16.1-0.20260609212700-45d3524fa885Low risk02026-06-10
v0.16.1-0.20260609143948-8d446b35193bLow risk02026-06-10
v0.16.1-0.20260609173255-6e4d5d1bef16Low risk02026-06-10
v0.16.1-0.20260608161418-8f3c42903170Low risk02026-06-09
v0.16.1-0.20260608214241-971a6126669aLow risk02026-06-09
v0.16.1-0.20260603210033-755e1bb67356Low risk02026-06-04
v0.15.1-0.20260515190800-3388065d78f6Low risk02026-06-04

Block this in CI

PkgRadar gates github.com/opentdf/platform/service (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/opentdf/platform/[email protected]