PkgRadar

Go modules · proxy.golang.org

github.com/tailscale/tsidp

Remote Payload

Why PkgRadar flagged v0.0.0-20260525202943-ccbf006c3539

SeveritySignalEvidence
mediumRemote Payloadgithub.com/tailscale/[email protected]/server/token.go
mediumRemote Payloadgithub.com/tailscale/[email protected]/server/userinfo.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260525202943-ccbf006c3539Review242026-06-25
v0.0.0-20250919200911-319e43da57edReview242026-06-25
v0.0.15-0.20260615153002-30df23b69459Review242026-06-25
v0.0.0-20250930175009-5fc324073b7dReview242026-06-25
v0.0.0-20251028214053-08d296dd6db8Review242026-06-25

Block this in CI

PkgRadar gates github.com/tailscale/tsidp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/tailscale/[email protected]