PkgRadar

Go modules · proxy.golang.org

github.com/siovos/siovos-audit

Credential file access: matched ".ssh/"

Why PkgRadar flagged v0.2.0

SeveritySignalEvidence
highCredential file accessmatched ".ssh/" · github.com/siovos/[email protected]/internal/checks/ssh/ssh.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.2.0High risk382026-06-04
v0.2.1-0.20260603163740-3fd3b6e2ad69High risk382026-06-04
v0.1.0High risk382026-06-03
v0.0.0-20260602200130-5893a80487e5High risk382026-06-03
v0.0.0-20260602194906-d919395580e2High risk382026-06-03
v0.0.0-20260602174837-d2af15c5b304High risk382026-06-03
v0.0.0-20260602172206-5466f645f982High risk382026-06-03
v0.0.0-20260529221534-b7ce5032c673Review82026-05-31

Block this in CI

PkgRadar gates github.com/siovos/siovos-audit (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/siovos/[email protected]