We don't have github.com/fxamacker/cbor/v2 (go) in the Gold index yet. Scan your dependencies to check it.
This verdict is generated from public data (known vulnerabilities, CISA KEV, OpenSSF Scorecard, and maintenance signals) and is guidance, not a guarantee. Always confirm which version you use with the full report and scan your actual manifest.