proxy.golang.org: consider blocking github.com/siruspen/logrus
#72116
Labels
NeedsInvestigation
Someone must examine and confirm this is a valid issue and not a duplicate of an existing one.
pkgsite/package-removal
Issues for package removal. See https://pkg.go.dev/about#removing-a-package
proxy.golang.org
golang/vulndb#3502 details an example of typo-squatting (
github.com/siru*sp*en/logrus
) a well-known Go module (github.com/siru*ps*en/logrus
).Though the squatted repo no longer exists on GitHub, it maintains an active entry in Go Module Proxy.
As the original reporter noted,
logger.go
maliciously specifies aninit
function:The text was updated successfully, but these errors were encountered: