PkgRadar

Go modules · proxy.golang.org

github.com/semgrep/semgrep-rules

Shipped Live Secret, Tls Verification Disabled, Messenger Bot Endpoint +1 more

Why PkgRadar flagged v0.0.0-20260617072517-d41fb34cf744

SeveritySignalEvidence
highShipped Live Secretgithub.com/semgrep/[email protected]/generic/secrets/gitleaks/aws-access-token.go
highShipped Live Secretgithub.com/semgrep/[email protected]/generic/secrets/gitleaks/github-app-token.go
highShipped Live Secretgithub.com/semgrep/[email protected]/generic/secrets/gitleaks/github-fine-grained-pat.go
highShipped Live Secretgithub.com/semgrep/[email protected]/generic/secrets/gitleaks/github-oauth.go
highShipped Live Secretgithub.com/semgrep/[email protected]/generic/secrets/gitleaks/github-pat.go
highShipped Live Secretgithub.com/semgrep/[email protected]/generic/secrets/gitleaks/github-refresh-token.go
highShipped Live Secretgithub.com/semgrep/[email protected]/generic/secrets/gitleaks/slack-access-token.go
mediumTls Verification Disabledgithub.com/semgrep/[email protected]/go/lang/security/audit/crypto/missing-ssl-minversion.fixed.go
mediumTls Verification Disabledgithub.com/semgrep/[email protected]/go/lang/security/audit/crypto/missing-ssl-minversion.go
mediumTls Verification Disabledgithub.com/semgrep/[email protected]/go/lang/security/audit/crypto/ssl.go
mediumTls Verification Disabledgithub.com/semgrep/[email protected]/go/lang/security/injection/tainted-url-host.go
mediumTls Verification Disabledgithub.com/semgrep/[email protected]/problem-based-packs/insecure-transport/go-stdlib/bypass-tls-verification.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260617072517-d41fb34cf744High risk1732026-06-24

Block this in CI

PkgRadar gates github.com/semgrep/semgrep-rules (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/semgrep/[email protected]