PkgRadar

Go modules · proxy.golang.org

github.com/tullo/crdb

Tls Verification Disabled: matched "--insecure"

Why PkgRadar flagged v0.0.0-20260618190003-6db0da5b9651

SeveritySignalEvidence
mediumTls Verification Disabledmatched "--insecure" · github.com/tullo/[email protected]/main.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260618190003-6db0da5b9651Review122026-06-20
v0.0.0-20260610213459-2ea6929e3182Low risk02026-06-12
v0.0.0-20260529181642-8c821589e22dLow risk02026-05-31
v0.0.0-20260527185233-14b1233c3541Low risk02026-05-29

Block this in CI

PkgRadar gates github.com/tullo/crdb (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/tullo/[email protected]