PkgRadar

Go modules · proxy.golang.org

github.com/victoriaMetrics/VictoriaMetrics

Remote Payload, Tls Verification Disabled, Credential file access +1 more

Why PkgRadar flagged v1.103.0-cluster

SeveritySignalEvidence
mediumRemote Payloadgithub.com/victoriametrics/[email protected]/app/vmalert/rule/utils.go
mediumRemote Payloadgithub.com/victoriametrics/[email protected]/app/vmalert/web.qtpl.go
mediumRemote Payloadgithub.com/victoriametrics/[email protected]/app/vmctl/vm_native.go
mediumTls Verification Disabledgithub.com/victoriametrics/[email protected]/lib/backup/s3remote/s3.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.103.0-clusterReview412026-06-23
v1.79.11-clusterReview172026-06-23
v1.39.0-clusterReview52026-06-23
v1.37.0-clusterReview52026-06-23
v1.139.0Review292026-06-23
v1.41.0-clusterReview52026-06-23
v1.93.8Review412026-06-23
v1.54.1Review172026-06-23
v1.64.0-clusterReview172026-06-23
v0.12.1-victorialogsReview412026-06-23
v1.18.7Low risk02026-06-23
v1.85.3Review412026-06-23
v1.28.2-clusterLow risk02026-06-23
v1.38.1-clusterReview52026-06-23
v1.110.10Review412026-06-23
v1.122.3Review412026-06-23
v1.145.1-0.20260619121831-9356c2111a0eReview292026-06-23
v1.119.0Review412026-06-23
v1.145.0Review292026-06-23

Block this in CI

PkgRadar gates github.com/victoriaMetrics/VictoriaMetrics (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/victoriaMetrics/[email protected]