PkgRadar

Go modules · proxy.golang.org

k8s.io/apimachinery

Tls Verification Disabled: matched "InsecureSkipVerify: true"

Why PkgRadar flagged v0.0.0-20260619004445-6bdb38e7395b

SeveritySignalEvidence
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · k8s.io/[email protected]/pkg/util/proxy/dial.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260619004445-6bdb38e7395bReview122026-06-20
v0.36.0-alpha.2.0.20260619004445-6bdb38e7395bReview122026-06-20
v0.0.0-20260619005300-111d7ab7ffafReview122026-06-20
v0.0.0-20260618165250-9b887553edddLow risk02026-06-19
v0.27.0-alpha.0.0.20221114163904-90df4d1d2d40Low risk02026-06-15
v0.36.0-alpha.2.0.20260612190757-f27849d49709Low risk02026-06-13
v0.0.0-20260612190757-f27849d49709Low risk02026-06-13
v0.33.13Low risk02026-06-13
v0.34.9Low risk02026-06-13
v0.35.6Low risk02026-06-13
v0.36.0-alpha.2.0.20260610191850-4e9e1931369bLow risk02026-06-11
v0.0.0-20260610191850-4e9e1931369bLow risk02026-06-11
v0.36.0-alpha.2.0.20260609072944-ff574143e0adLow risk02026-06-10
v0.0.0-20260609072944-ff574143e0adLow risk02026-06-10
v0.0.0-20260603230146-e1f41aba69e0Low risk02026-06-05
v0.36.0-alpha.2.0.20260603193353-086fd453321cLow risk02026-06-05
v0.36.0-alpha.2.0.20260603230146-e1f41aba69e0Low risk02026-06-05
v0.0.0-20260602192419-f1a3b2b13478Low risk02026-06-03
v0.36.0-alpha.2.0.20260528165152-23de3b4e1a5dLow risk02026-05-29
v0.0.0-20260528165152-23de3b4e1a5dLow risk02026-05-29

Block this in CI

PkgRadar gates k8s.io/apimachinery (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go k8s.io/[email protected]