How to get in touch about a security concern?

This issue has been created since 2022-11-14.

Hi, I found an important security problem in goutil, how can I get in touch with you in a private way and submit my security report?

inhere wrote this answer on 2022-12-07

hi @cokeBeer Can you send a PR to fix it. :)

cokeBeer wrote this answer on 2022-12-07

Yes, I do would like to submit a PR to help you fix it. But directly PR may disclose the detail of the vulnerability too early and lead to some exploits by others. So in regular progress, as a security researcher, I need a safe way to submit my report to you, the matainer, and prove the danger of the vulnerability first. Both email or qq will be ok.
Github also suggests this, too. More information can be found in

inhere wrote this answer on 2022-12-07

OK, thanks. My email is [email protected]

cokeBeer wrote this answer on 2022-12-07

I have sent my report to you. If you accept this vulnerability, please let me know.

inhere wrote this answer on 2022-12-07

👍 Thanks, 已经收到。


cokeBeer wrote this answer on 2023-03-04

@inhere Hi , would you like to publish a security advisory for this vulnerability?

inhere wrote this answer on 2023-03-04

@cokeBeer Hi, what do i need to do?

cokeBeer wrote this answer on 2023-03-04

@inhere Hi, Can you see New draft security advisory in Click the button and you can create new security advisory. If you feel confused about some blanks, you can invite me as a collaborator to edit it.

cokeBeer wrote this answer on 2023-03-04

@inhere any questions ?

cokeBeer wrote this answer on 2023-03-04

@inhere Maybe you can take this one as a reference, a security advisory published by another famous golang tool library, lancet: GHSA-pp3f-xrw5-q5j4

inhere wrote this answer on 2023-03-04
cokeBeer wrote this answer on 2023-03-04

@inhere Hi, the page is 404 for me. Did you invite me as a collabrator?

inhere wrote this answer on 2023-03-05

Hi @cokeBeer , Added you as a contributor

cokeBeer wrote this answer on 2023-03-06

@inhere Hi, I have finished the security advisory content. Could you request a CVE identification number in that page before publish it ? (Only maintainers can do so)

inhere wrote this answer on 2023-03-06

OK. Do i need to publish it?

cokeBeer wrote this answer on 2023-03-06

@inhere Yes, this can inform users of goutil to upgrade to more secure version.

inhere wrote this answer on 2023-03-07

hi, the GHSA has been published.

More Details About Repo
Owner Name gookit
Repo Name goutil
Full Name gookit/goutil
Language Go
Created Date 2018-07-03
Updated Date 2023-03-22
Star Count 1263
Watcher Count 29
Fork Count 142
Issue Count 3


