protoc-gen-gotemplate icon indicating copy to clipboard operation
protoc-gen-gotemplate copied to clipboard

[security] replace moul.io refs with github.com

Open amalone-scwx opened this issue 4 years ago • 0 comments

The go.mod and source code references moul.io/protoc-gen-gotemplate rather than github.com/moul/protoc-gen-gotemplate. Using a personal DNS is a potential security problem, as the code could be changed from that published on GitHub. To protect against this, projects that use this repo would have to qualify all refs with hashes rather than just the version.

I am guessing that you do this to make it easier to test locally and override the domain name? I'm not a fan of how Go uses URL refs, rather than published package refs to crates.io or the like.

In any case, is there a chance you can revert the source back to using GitHub.com urls?

amalone-scwx avatar Nov 03 '20 19:11 amalone-scwx