Go modules · proxy.golang.org
github.com/sigstore/FULCIO
Tls Verification Disabled, Credential file access
Why PkgRadar flagged v1.8.8-0.20260616212655-16cc54efe85e
| Severity | Signal | Evidence |
|---|---|---|
| medium | Tls Verification Disabled | github.com/sigstore/[email protected]/cmd/app/http.go |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v1.8.8-0.20260616212655-16cc54efe85e | Review | 15 | 2026-06-21 |
v1.8.7 | Review | 15 | 2026-06-21 |
Block this in CI
pkgradar gate --ecosystem go github.com/sigstore/[email protected]