mastodon.sdf.org is part of the decentralized social network powered by Mastodon.
"I appreciate SDF but it's a general-purpose server and the name doesn't make it obvious that it's about art." - Eugen Rochko

Administered by:

Server stats:

2.6K
active users

Learn more

benz

I just ran on all of , and there are a lot more vulnerable packages than I thought :(

I started fixing the finds in . Some of these have no fix upstream!

@bentsukun soo, do I guess right that it needs the output of a make patch of a go package to check it?
And only works on go packages?

@spz Yes, exactly. But on the plus side, it does static analysis to check if any of the vulnerable code is actually called.