PkgRadar

Go modules · proxy.golang.org

gitlab.torproject.org/cerberus-droid/torgo-v2

Tls Verification Disabled: matched "InsecureSkipVerify: true"

Why PkgRadar flagged v0.0.0-20260619013054-5479775bcc84

SeveritySignalEvidence
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · gitlab.torproject.org/cerberus-droid/[email protected]/cmd/conflux-test/main.go
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · gitlab.torproject.org/cerberus-droid/[email protected]/cmd/ddg-title/main.go
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · gitlab.torproject.org/cerberus-droid/[email protected]/cmd/load-onion-socks/main.go
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · gitlab.torproject.org/cerberus-droid/[email protected]/cmd/load-onion/main.go
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · gitlab.torproject.org/cerberus-droid/[email protected]/cmd/test_onion_socks/main.go
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · gitlab.torproject.org/cerberus-droid/[email protected]/cmd/torgo-duck-title/main.go
mediumRemote Payloadmatched "cURL " · gitlab.torproject.org/cerberus-droid/[email protected]/internal/core/directory/client.go
mediumRemote Payloadmatched "cURL " · gitlab.torproject.org/cerberus-droid/[email protected]/internal/feature/directory/dirclient/client.go
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · gitlab.torproject.org/cerberus-droid/[email protected]/internal/network/conn.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260619013054-5479775bcc84Review742026-06-20
v0.0.0-20260619010157-3f4a0fb0145dReview482026-06-20

Block this in CI

PkgRadar gates gitlab.torproject.org/cerberus-droid/torgo-v2 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go gitlab.torproject.org/cerberus-droid/[email protected]