PkgRadar

npm · registry.npmjs.org

@libp2p/tls

Tls Verification Disabled: matched "rejectUnauthorized: false"

Why PkgRadar flagged 3.1.4-bfb7ceb0f

SeveritySignalEvidence
mediumTls Verification Disabledmatched "rejectUnauthorized: false" · package/dist/src/tls.js
mediumTls Verification Disabledmatched "rejectUnauthorized: false" · package/src/tls.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
3.1.4-bfb7ceb0fReview72026-06-20
3.1.4-d4dad9bf5Review72026-06-20
3.1.4Low risk02026-06-13
3.1.3-5e07d5963Low risk02026-06-13
3.1.3-404c7824aLow risk02026-06-12
3.1.3-7ae12f9b0Low risk02026-06-06
3.1.3-a34745c01Low risk02026-06-05
3.1.3Low risk02026-05-31
3.1.2-160a24585Low risk02026-05-30
3.1.2-5b8813abcLow risk02026-05-30
3.1.2-b7c6dc0f2Low risk02026-05-29
3.1.2-29797a5bbLow risk02026-05-29
3.1.2-d888f182fLow risk02026-05-27
3.1.2-ed1ad1f26Low risk02026-05-25
3.1.2-d59c165acLow risk02026-05-25
3.1.2-3574648c3Low risk02026-05-25

Block this in CI

PkgRadar gates @libp2p/tls (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @libp2p/[email protected]