PkgRadar

Go modules · proxy.golang.org

shanhu.io/g

Tls Verification Disabled: matched "InsecureSkipVerify: true"

Why PkgRadar flagged v0.0.0-20260618230917-ff701b4417ae

SeveritySignalEvidence
mediumTls Verification Disabledmatched "InsecureSkipVerify: true" · shanhu.io/[email protected]/https/httpstest/tls_configs.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.0-20260618230917-ff701b4417aeReview122026-06-20
v0.0.0-20260607101119-4e47b6d39f1bLow risk02026-06-10
v0.0.0-20260531000654-222bf12a0a3aLow risk02026-06-03
v0.0.0-20260529084151-c5cd614e372bLow risk02026-05-30
v0.0.0-20260529082859-7f12d25fd4e1Low risk02026-05-30
v0.0.0-20260529055848-9fe448140892Low risk02026-05-30
v0.0.0-20260528170008-2fb0bfbcadc5Low risk02026-05-29

Block this in CI

PkgRadar gates shanhu.io/g (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go shanhu.io/[email protected]
shanhu.io/g — Go modules security scan | PkgRadar