15,000 Go Module Repositories on GitHub Vulnerable to Repojacking Attack

This page summarizes the projects mentioned and recommended in the original post on /r/golang

Our great sponsors
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • WorkOS - The modern identity platform for B2B SaaS
  • SaaSHub - Software Alternatives and Reviews
  • crates.io

    The Rust package registry

  • Rust does it so much better with https://crates.io . I don't know why Go can't (or won't) do something similar.

  • icingadb

    Icinga configuration and state database supporting multiple environments

  • First off I'm not a security person. This can go deep from the mod/sum file hash managers to the commits hash managers, to the repo hash managers, to hashes and time stamps in the go binary. https://github.com/Icinga/icingadb/pull/487

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts