PkgRadar

Go modules · proxy.golang.org

github.com/sigstore/fulcio

Credential file access: matched ".config/gcloud"

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.8.8-0.20260615145658-602f013b7387Review32026-06-16
v1.8.8-0.20260615130852-e3bcb366362eReview32026-06-16
v0.0.0-20260601085741-e808f25e3cf0Review32026-06-04
v1.8.8-0.20260601085741-e808f25e3cf0Review32026-06-02
v1.8.8-0.20260529205617-362e11d2196fReview32026-05-30
v1.8.7Review32026-05-30

Block this in CI

PkgRadar gates github.com/sigstore/fulcio (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/sigstore/[email protected]