PkgRadar

Go modules · proxy.golang.org

github.tiyicn.workers.dev/cilium/cilium

Remote Payload, Tls Verification Disabled, Credential file access

Why PkgRadar flagged v1.20.0-pre.3.0.20260624212407-eb07b0262e39

SeveritySignalEvidence
mediumRemote Payloadgithub.tiyicn.workers.dev/cilium/[email protected]/cilium-cli/cli/connectivity.go
mediumTls Verification Disabledgithub.tiyicn.workers.dev/cilium/[email protected]/cilium-cli/cli/connectivity.go
mediumRemote Payloadgithub.tiyicn.workers.dev/cilium/[email protected]/cilium-cli/cli/version.go
mediumTls Verification Disabledgithub.tiyicn.workers.dev/cilium/[email protected]/cilium-cli/connectivity/check/context.go
mediumTls Verification Disabledgithub.tiyicn.workers.dev/cilium/[email protected]/pkg/auth/mutual_authhandler.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.20.0-pre.3.0.20260624212407-eb07b0262e39Review632026-06-26
v1.19.5Review152026-06-26

Block this in CI

PkgRadar gates github.tiyicn.workers.dev/cilium/cilium (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.tiyicn.workers.dev/cilium/[email protected]