Tinyumbrella v79/5/2023 ![]() ![]() For modules fetched via the proxy, the VCS commands are performed by the proxy server (in a sandbox) rather than on the user's local machine. Go 1.13 by de fault uses the public Go module proxy () to fetch modules that are publicly available. The default setting for that variable somewhat reduces the VCS tools used by `go get` as compared with previous releases. Go 1.16 will add support for enabling or disabling specific version-control tools based on import paths via the GOVCS environment variable ( ). While I agree that users should continue to be careful about their code dependencies, I just wanted to note a few features that can hopefully help to provide more defense in depth. ![]() First off, thanks for investigating and reporting security issues in the go command!
0 Comments
Leave a Reply.AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |