Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(go): fix possible dependency spoofing. #96

Merged
merged 2 commits into from
Jan 18, 2022
Merged

chore(go): fix possible dependency spoofing. #96

merged 2 commits into from
Jan 18, 2022

Conversation

Zenithar
Copy link
Contributor

Context

golangci-lint imports a dependency go-header from github.com/denis-tingajkin/go-header which is not existing any more and redirect the dependency to github.com/denis-tingaikin/go-header (j vs i).

The denis-tingajkin could be claimed and used to publish a fakego-header which will be used to pollute the tool.

Reference(s)

@Zenithar Zenithar self-assigned this Jan 18, 2022
@Zenithar Zenithar merged commit 2d7248d into elastic:main Jan 18, 2022
@Zenithar Zenithar deleted the fix_sec_possible_dependency_spoofing branch January 18, 2022 22:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant