PkgRadar

Go modules · proxy.golang.org

k8s.io/client-go

Tls Verification Disabled: matched "InsecureSkipVerify: true"

Why PkgRadar flagged v0.0.0-20260619010447-d04ac3067ff1

SeveritySignalEvidence
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · k8s.io/[email protected]/util/cert/server_inspection.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260619010447-d04ac3067ff1Review122026-06-20
v6.0.1-0.20180804021835-c4528e977819+incompatibleLow risk02026-06-19
v0.0.0-20260618010404-c18a3de8a3b7Low risk02026-06-19
v0.0.0-20260617153444-f226f2f6e653Low risk02026-06-18
v0.0.0-20260617073434-1e5bbe84525fLow risk02026-06-18
v0.0.0-20260615233408-9fb400dccd3fLow risk02026-06-17
v0.34.9Low risk02026-06-13
v0.35.6Low risk02026-06-13
v0.33.13Low risk02026-06-13
v0.36.2Low risk02026-06-13
v0.0.0-20260611041423-394ed525a635Low risk02026-06-12
v0.37.0-alpha.1Low risk02026-06-12
v0.0.0-20260610001234-cfe83ef28cccLow risk02026-06-11
v11.0.0-20190115164855-701b91367003+incompatibleLow risk02026-06-10
v0.0.0-20260606033559-0deb0beab371Low risk02026-06-07
v0.0.0-20260603193553-6b1bbb2a13daLow risk02026-06-04
v0.0.0-20251218142908-d008946b234bLow risk02026-05-30
v0.0.0-20260528010126-3f75409d2aafLow risk02026-05-30
v0.0.0-20260528210130-5d252d37f730Low risk02026-05-29

Block this in CI

PkgRadar gates k8s.io/client-go (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go k8s.io/[email protected]