jpillora / jpillora/chisel

Vulnerabilities in go packages

Open
#423 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
16.6k
Forks
1.6k
PR merge metrics
No merged PRs in 30d

Description

I'm making my own Docker image using the pre-built chisel 1.8.1 binaries from the releases page and Docker is telling me that four of the go packages contain vulnerabilities:

Screenshot 2023-04-19 at 16 56 26

Are these safe to use or should I be looking to build from source using fixed versions of the go packages?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the chisel 1.8.1 binaries on the linked releases page and the Docker vulnerability report shown in the issue. Identify the four reported Go package vulnerabilities and determine whether they affect the pre-built binaries or require rebuilding from source; done means documenting a clear safety or remediation conclusion.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, go
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.