PkgRadar

Go modules · proxy.golang.org

github.com/oracle/crossplane-provider-oci

Shell Credential File Read, Go Generate Shell, Remote Payload +1 more

Why PkgRadar flagged v1.2.0

SeveritySignalEvidence
highShell Credential File Readgithub.com/oracle/[email protected]/apis/cluster/database/v1alpha1/zz_cloudvmcluster_types.go
highShell Credential File Readgithub.com/oracle/[email protected]/apis/cluster/database/v1alpha1/zz_keystore_types.go
highShell Credential File Readgithub.com/oracle/[email protected]/apis/cluster/database/v1alpha1/zz_toolsdatabasetoolsconnection_types.go
highShell Credential File Readgithub.com/oracle/[email protected]/apis/namespaced/database/v1alpha1/zz_cloudvmcluster_types.go
highShell Credential File Readgithub.com/oracle/[email protected]/apis/namespaced/database/v1alpha1/zz_keystore_types.go
highShell Credential File Readgithub.com/oracle/[email protected]/apis/namespaced/database/v1alpha1/zz_toolsdatabasetoolsconnection_types.go
mediumGo Generate Shellgithub.com/oracle/[email protected]/apis/generate.go
mediumRemote Payloadgithub.com/oracle/[email protected]/apis/cluster/fusionapps/v1alpha1/zz_fusionenvironment_types.go
mediumRemote Payloadgithub.com/oracle/[email protected]/apis/cluster/fusionapps/v1alpha1/zz_generated.deepcopy.go
mediumRemote Payloadgithub.com/oracle/[email protected]/apis/namespaced/fusionapps/v1alpha1/zz_fusionenvironment_types.go
mediumRemote Payloadgithub.com/oracle/[email protected]/apis/namespaced/fusionapps/v1alpha1/zz_generated.deepcopy.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.2.0High risk1512026-06-26

Block this in CI

PkgRadar gates github.com/oracle/crossplane-provider-oci (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/oracle/[email protected]