Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

I'm worried people will forget this is turned off and not realize we're exposing ourselves #12

Open
n3wscott opened this issue Nov 3, 2020 · 4 comments

Comments

@n3wscott
Copy link

n3wscott commented Nov 3, 2020

I'm worried people will forget this is turned off and not realize we're exposing ourselves

Can we add retries for CI?

Originally posted by @dprotaso in #10 (comment)

@dprotaso
Copy link
Member

@krsna-m
Copy link
Contributor

krsna-m commented Sep 19, 2023

Slack context is lost please reopen with context whenever

@krsna-m krsna-m closed this as completed Sep 19, 2023
@dprotaso
Copy link
Member

dprotaso commented Sep 19, 2023

Context:

When we fetch dependencies we were getting 4xx errors because they didn't show up in the module mirror and checksum database (there's a bit of a delay). To avoid this we turned off using the mirror and the checksum db. Doing this opens us up to a potential supply chain attack - since we aren't verifying the sums.

Settings are here: https://go.dev/ref/mod#checksum-database

@dprotaso dprotaso reopened this Sep 19, 2023
@dprotaso
Copy link
Member

I think the env var settings let you tweak which modules we do verification on - that could be an minimal option here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants