PkgRadar

Go modules · proxy.golang.org

github.com/warky-devs/resolvespec

Shell Credential File Read, Obfuscation Density

Why PkgRadar flagged v1.1.15

SeveritySignalEvidence
highShell Credential File Readgithub.com/warky-devs/[email protected]/pkg/security/keystore.go
highShell Credential File Readgithub.com/warky-devs/[email protected]/pkg/security/keystore_authenticator.go
highShell Credential File Readgithub.com/warky-devs/[email protected]/pkg/security/keystore_config.go
highShell Credential File Readgithub.com/warky-devs/[email protected]/pkg/security/keystore_database.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.1.15High risk1002026-06-24
v1.1.13High risk1002026-06-24
v1.1.12High risk1002026-06-24
v1.1.11-0.20260608131358-c120b49529f9Low risk02026-06-11
v1.1.10Low risk02026-06-11
v1.1.9Low risk02026-06-08
v1.1.7Low risk02026-06-07
v1.1.6Low risk02026-06-05
v1.1.3Low risk02026-06-03
v1.1.4Low risk02026-06-03

Block this in CI

PkgRadar gates github.com/warky-devs/resolvespec (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/warky-devs/[email protected]