PkgRadar

Go modules · proxy.golang.org

github.com/smartcontractkit/chainlink-relay

Shell Credential File Read

Why PkgRadar flagged v0.11.2-0.20260622205851-5fe4f9bdcd4a

SeveritySignalEvidence
highShell Credential File Readgithub.com/smartcontractkit/[email protected]/pkg/loop/internal/pb/keystore/keystore_grpc.pb.go
highShell Credential File Readgithub.com/smartcontractkit/[email protected]/pkg/loop/internal/pb/keystore_grpc.pb.go
highShell Credential File Readgithub.com/smartcontractkit/[email protected]/pkg/loop/internal/types/types.go
highShell Credential File Readgithub.com/smartcontractkit/[email protected]/pkg/loop/keystore_service.go
highShell Credential File Readgithub.com/smartcontractkit/[email protected]/pkg/loop/plugin_keystore.go
highShell Credential File Readgithub.com/smartcontractkit/[email protected]/pkg/loop/plugin_relayer.go
highShell Credential File Readgithub.com/smartcontractkit/[email protected]/pkg/types/core/keystore.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.11.2-0.20260622205851-5fe4f9bdcd4aHigh risk952026-06-24
v0.0.0-20260622205851-5fe4f9bdcd4aHigh risk952026-06-24
v0.11.2-0.20260616172018-16271fdba62cLow risk02026-06-18
v0.0.0-20260616172018-16271fdba62cLow risk02026-06-18
v0.11.2-0.20260615162843-0bc5f4146869Low risk02026-06-17
v0.0.0-20260615162843-0bc5f4146869Low risk02026-06-17
v0.11.2-0.20260605114954-0a11f78477a0Low risk02026-06-06
v0.0.0-20260605114954-0a11f78477a0Low risk02026-06-06
v0.11.2-0.20260604214100-1eaba040a636Low risk02026-06-06
v0.0.0-20260604214100-1eaba040a636Low risk02026-06-06
v0.0.0-20260601100130-d1ced0e51eb4Low risk02026-06-02
v0.11.2-0.20260601100130-d1ced0e51eb4Low risk02026-06-02
v0.0.0-20260601093702-68a108a97b75Low risk02026-06-02
v0.0.0-20260528150532-b12054695b25Low risk02026-05-29
v0.0.0-20260527134213-55d3497f220eLow risk02026-05-29

Block this in CI

PkgRadar gates github.com/smartcontractkit/chainlink-relay (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/smartcontractkit/[email protected]