Tuesday, April 22, 2025
HomeGolangGo 1.24.0 launch bundle oversharing? - Technical Dialogue

Go 1.24.0 launch bundle oversharing? – Technical Dialogue


Hello,
I’ve simply put in go 1.24.0 into our construct toolchain and anchore is now throwing up all types of previous vulnerabilities on the next file:
/usr/native/go/src/debug/buildinfo/testdata/go117

I be aware that the buildinfo/testdata sub-directory doesn’t exist within the 1.23.6 launch (or prior).

Actually the testdata subdirectory now seems all over the place, however it’s go117 that’s inflicting the issue.

Can I assume the inclusion of the */testdata sub listing is a packaging error and take away the folder?

Paul.

Can I assume the inclusion of the */testdata sub listing is a packaging error and take away the folder?

It was added 7 months in the past in 28aed40. From a fast look it appears like the entire of the src tree results in the discharge archives.

I can’t discover any subject at points, both open or closed, regarding the listing. If it was inflicting issues for a number of individuals I’d have anticipated there to be a difficulty by now.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments