Skip to content

Conversation

Zenithar
Copy link
Contributor

Context

golangci-lint imports a dependency go-header from github.com/denis-tingajkin/go-header which is not existing any more and redirect the dependency to github.com/denis-tingaikin/go-header (j vs i).

The denis-tingajkin could be claimed and used to publish a fakego-header which will be used to pollute the tool.

Reference(s)

@Zenithar Zenithar self-assigned this Jan 18, 2022
@Zenithar Zenithar merged commit 2d7248d into elastic:main Jan 18, 2022
@Zenithar Zenithar deleted the fix_sec_possible_dependency_spoofing branch January 18, 2022 22:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant