DragonFly has weak integrity checks for downloaded files in d7y.io/dragonfly
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2025-3973" }
"https://vuln.go.dev/ID/GO-2025-3973.json"