PkgRadar

Go modules · proxy.golang.org

github.com/werf/3p-go-tuf

Tls Verification Disabled: matched "--insecure"

Why PkgRadar flagged v0.0.0-20210521115116-4d5d8ffd7b1a

SeveritySignalEvidence
mediumTls Verification Disabledmatched "--insecure" · github.com/werf/[email protected]/cmd/tuf/main.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20210521115116-4d5d8ffd7b1aReview122026-06-20
v0.0.0-20220617164744-986a4c5a492bLow risk02026-06-16

Block this in CI

PkgRadar gates github.com/werf/3p-go-tuf (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/werf/[email protected]