Go modules · proxy.golang.org
github.com/siovos/siovos-audit
Credential file access: matched ".ssh/"
Why PkgRadar flagged v0.2.0
| Severity | Signal | Evidence |
|---|---|---|
| high | Credential file access | matched ".ssh/" · github.com/siovos/[email protected]/internal/checks/ssh/ssh.go |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v0.2.0 | High risk | 38 | 2026-06-04 |
v0.2.1-0.20260603163740-3fd3b6e2ad69 | High risk | 38 | 2026-06-04 |
v0.1.0 | High risk | 38 | 2026-06-03 |
v0.0.0-20260602200130-5893a80487e5 | High risk | 38 | 2026-06-03 |
v0.0.0-20260602194906-d919395580e2 | High risk | 38 | 2026-06-03 |
v0.0.0-20260602174837-d2af15c5b304 | High risk | 38 | 2026-06-03 |
v0.0.0-20260602172206-5466f645f982 | High risk | 38 | 2026-06-03 |
v0.0.0-20260529221534-b7ce5032c673 | Review | 8 | 2026-05-31 |
Block this in CI
pkgradar gate --ecosystem go github.com/siovos/[email protected]