bottlerocket-os / bottlerocket-os/bottlerocket-core-kit
Add `libstd-go` package
Open
- Dominant language
- Rust
- Stars
- 34
- Forks
- 77
- Avg merge
- 2d 23h
- Merged PRs (30d)
- 23
Description
**What I'd like:**
Currently, Bottlerocket does not have a clear way to report Go advisories from CVEs patched in the `bottlerocket-sdk` repository.
One solution is to add a no-op `libstd-go` package to the core-kit that we tag Go vulnerabilities to, which would simplify the BRSAs for them.
**Any alternatives you've considered:**
N/A
Contributor guide
Research direction
Start by tracing how package definitions are added in core-kit and how Go CVEs from the bottlerocket-sdk repository are represented in BRSAs. Done means a no-op libstd-go package exists in core-kit and can be used to tag the relevant Go advisories.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- build-system, security
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100