ko-build / ko-build/ko

By default build with -buildmode=pie when available

Open
#375 4 comments 0 reactions 0 assignees View on GitHub
lifecycle/frozen
Dominant language
Go
Stars
8.5k
Forks
447
PR merge metrics
No merged PRs in 30d

Description

I believe this would enable https://en.wikipedia.org/wiki/Address_space_layout_randomization and help our security posture

Contributor guide

Open the contributing guide

Research direction

No files, tests, or entry points are identified in the issue. Start by locating where ko configures Go build flags, then determine how to enable -buildmode=pie only when supported; done means default builds use PIE where available without breaking unsupported environments.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
build-system, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.