We found the patch versions not appeared in Golang Index. #1351
Closed
Silence-worker-02
started this conversation in
Ideas
Replies: 2 comments
-
@fiftin Just tagging you so the problem with |
Beta Was this translation helpful? Give feedback.
0 replies
-
The golang index is primary relevant for libraries, but Semaphore is not a library. And since Semaphore is not follwing the module naming for libraries it is not even possible to get this fixed correctly:
|
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hello, we are a research team working on Golang. During our investigation, we discovered that the CVE-2023-28609 was addressed and the patch versions were released. However, we noticed that these patch versions have not appeared in the Golang Index, which means that 'go list' cannot automatically push the patch versions to downstream users.
We recommend that after releasing the versions, you push them to the Golang Index using the command 'go get github.com/ansible-semaphore/semaphore@version'. This will enable the automatic distribution of the patch versions to downstream users. Thank you for your attention.
Beta Was this translation helpful? Give feedback.
All reactions