google / google/go-containerregistry

🚨 Security Vulnerability Report

Open
#2,346 1 comment 0 reactions 0 assignees View on GitHub
lifecycle/stale
Dominant language
Go
Stars
4k
Forks
686
Avg merge
2d 12h
Merged PRs (30d)
26

Description

Hey Google Team,

Just a friendly ping to let you know that I've reported a security vulnerability here:
- https://github.com/google/go-containerregistry/security/advisories/GHSA-qfxf-rcm3-cc77
- https://issuetracker.google.com/issues/522788246

## Disclosure Policy

**This vulnerability disclosure follows the Open Source Security Foundation's [90-day vulnerability disclosure policy](https://openssf.org/about/vulnerability-disclosure-policy/). Full disclosure will occur either at the end of the 90-day deadline or whenever a patch is made widely available, whichever occurs first. We kindly request a response and confirmation of intention to fix from the maintainer within 21 days of our initial report.**

Contributor guide

Open the contributing guide

Research direction

Review the linked GitHub security advisory and Google Issue Tracker entry first; the issue body does not identify files, tests, or an entry point. Done is not defined in this issue beyond maintainer response and vulnerability handling.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.