PkgRadar

Go modules · proxy.golang.org

github.com/smartcontractkit/chainlink-common/keystore

Shell Credential File Read

Why PkgRadar flagged v1.2.1-0.20260623104656-f39eba3e2bc6

SeveritySignalEvidence
highShell Credential File Readgithub.com/smartcontractkit/chainlink-common/[email protected]/core_keystore.go
highShell Credential File Readgithub.com/smartcontractkit/chainlink-common/[email protected]/keystore.go
highShell Credential File Readgithub.com/smartcontractkit/chainlink-common/[email protected]/kms/fake_client.go
highShell Credential File Readgithub.com/smartcontractkit/chainlink-common/[email protected]/kms/keystore.go
highShell Credential File Readgithub.com/smartcontractkit/chainlink-common/[email protected]/serialization/keystore.pb.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.2.1-0.20260623104656-f39eba3e2bc6High risk1002026-06-24
v1.2.1-0.20260616124219-bdae88e1c732Low risk02026-06-17
v1.2.1-0.20260615162843-0bc5f4146869Low risk02026-06-16
v0.0.0-20260615174008-ad4255cae51cLow risk02026-06-16
v0.0.0-20260615172104-c4c0d51d7337Low risk02026-06-16
v0.0.0-20260615164219-62611db3caaaLow risk02026-06-16
v1.2.1-0.20260615154415-2bc73adfe23cLow risk02026-06-16
v0.0.0-20260615160054-7fbe64d8f131Low risk02026-06-16
v1.2.1-0.20260609131617-0b659faac692Low risk02026-06-10
v1.2.1-0.20260609085708-ad25dc28b02fLow risk02026-06-10
v1.2.1-0.20260609093307-4fe1b4ba899eLow risk02026-06-10
v1.2.0Low risk02026-06-06
v1.1.1-0.20260603162703-43f4fa4bd88cLow risk02026-06-05
v1.1.1-0.20260602101458-208ae6ddea43Low risk02026-06-05
v1.1.1-0.20260529092756-a94bc8ce96d6Low risk02026-05-30
v1.1.1-0.20260528214726-cf893cdf4118Low risk02026-05-30
v1.1.1-0.20260528041622-3391dc19c200Low risk02026-05-29
v1.1.1-0.20260527134213-55d3497f220eLow risk02026-05-29
v1.1.1-0.20260528011950-2a85a9c43367Low risk02026-05-29

Block this in CI

PkgRadar gates github.com/smartcontractkit/chainlink-common/keystore (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/smartcontractkit/chainlink-common/[email protected]