all dependencies". The justification was to push the latest security fixes immediately, but more often these days it pushes the latest malware immediately instead. https://bsky.app/profile/swtch.com/post/3mitflkura32v 6
GO-2024-2947 Leak of sensitive information to log files in github.com/hashicorp/go-retryablehttp More info: https://pkg.go.dev/vuln/GO-2024-2947 Module: github.com/hashicorp/go-retryablehttp 19
#1: GO-2026-5039 Arbitrary inputs are included in errors without any escaping in net/textproto More info: https://pkg.go.dev/vuln/GO-2026-5039 Fixed in: net/[email protected] 20