PkgRadar

Go modules · proxy.golang.org

github.com/wzshiming/kwok

Reverse Shell, Remote Payload, Tls Verification Disabled

Why PkgRadar flagged v0.8.0-alpha.3.0.20260623064325-a960bd99873b

SeveritySignalEvidence
highReverse Shellgithub.com/wzshiming/[email protected]/pkg/kwokctl/runtime/kind/cluster_port_forward.go
mediumRemote Payloadgithub.com/wzshiming/[email protected]/pkg/consts/consts.go
mediumTls Verification Disabledgithub.com/wzshiming/[email protected]/pkg/kwokctl/components/dashboard.go
mediumTls Verification Disabledgithub.com/wzshiming/[email protected]/pkg/kwokctl/components/kube_apiserver.go
mediumTls Verification Disabledgithub.com/wzshiming/[email protected]/pkg/kwokctl/components/kube_controller_manager.go
mediumTls Verification Disabledgithub.com/wzshiming/[email protected]/pkg/kwokctl/components/kube_scheduler.go
mediumTls Verification Disabledgithub.com/wzshiming/[email protected]/pkg/kwokctl/components/metrics_server.go
mediumTls Verification Disabledgithub.com/wzshiming/[email protected]/pkg/kwokctl/runtime/kind/cluster_etcd.go
mediumTls Verification Disabledgithub.com/wzshiming/[email protected]/pkg/kwokctl/runtime/kind/cluster_kube_apiserver.go
mediumTls Verification Disabledgithub.com/wzshiming/[email protected]/pkg/kwokctl/runtime/kind/cluster_kube_controller_manager.go
mediumTls Verification Disabledgithub.com/wzshiming/[email protected]/pkg/kwokctl/runtime/kind/cluster_kube_scheduler.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.8.0-alpha.3.0.20260623064325-a960bd99873bHigh risk1142026-06-26
v0.8.0-alpha.2High risk1142026-06-26
v0.8.0-alpha.3High risk1142026-06-26

Block this in CI

PkgRadar gates github.com/wzshiming/kwok (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/wzshiming/[email protected]