Go modules · proxy.golang.org
github.com/treeverse/lakeFs
Shipped Live Secret, Tls Verification Disabled, Credential file access +1 more
Why PkgRadar flagged v1.82.1-0.20260621194359-4cf60fdbadbb
| Severity | Signal | Evidence |
|---|---|---|
| high | Shipped Live Secret | github.com/treeverse/[email protected]/.gitleaks.toml |
| high | Shipped Live Secret | github.com/treeverse/[email protected]/pkg/config/defaults.go |
| medium | Tls Verification Disabled | github.com/treeverse/[email protected]/pkg/block/s3/adapter.go |
| medium | Tls Verification Disabled | github.com/treeverse/[email protected]/pkg/testutil/cosmosdb.go |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v1.82.1-0.20260621194359-4cf60fdbadbb | High risk | 105 | 2026-06-23 |
Block this in CI
pkgradar gate --ecosystem go github.com/treeverse/[email protected]