PkgRadar

Go modules · proxy.golang.org

gitlab.com/gitlab-org/ci-cd/docker-machine

Tls Verification Disabled, Remote Payload, Credential file access

Why PkgRadar flagged v0.16.2-gitlab.48

SeveritySignalEvidence
mediumTls Verification Disabledgitlab.com/gitlab-org/ci-cd/[email protected]/libmachine/provision/boot2docker.go
mediumTls Verification Disabledgitlab.com/gitlab-org/ci-cd/[email protected]/libmachine/provision/coreos.go
mediumTls Verification Disabledgitlab.com/gitlab-org/ci-cd/[email protected]/libmachine/provision/generic.go
mediumTls Verification Disabledgitlab.com/gitlab-org/ci-cd/[email protected]/libmachine/provision/google_cos.go
mediumRemote Payloadgitlab.com/gitlab-org/ci-cd/[email protected]/libmachine/provision/rancheros.go
mediumTls Verification Disabledgitlab.com/gitlab-org/ci-cd/[email protected]/libmachine/provision/redhat.go
mediumTls Verification Disabledgitlab.com/gitlab-org/ci-cd/[email protected]/libmachine/provision/systemd.go
mediumRemote Payloadgitlab.com/gitlab-org/ci-cd/[email protected]/libmachine/provision/utils.go
mediumCredential file accessgitlab.com/gitlab-org/ci-cd/[email protected]/drivers/digitalocean/digitalocean.go
mediumCredential file accessgitlab.com/gitlab-org/ci-cd/[email protected]/drivers/vmwarefusion/fusion_darwin.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.16.2-gitlab.48Review1142026-06-25
v0.16.2-gitlab.50Review1142026-06-25
v0.16.2-gitlab.49Review1142026-06-25

Block this in CI

PkgRadar gates gitlab.com/gitlab-org/ci-cd/docker-machine (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go gitlab.com/gitlab-org/ci-cd/[email protected]