agollo
agollo copied to clipboard
An elegant Go client for Ctrip Apollo
data:image/s3,"s3://crabby-images/ac75a/ac75a8621a71dfe14bd73dfd49155003d08ca369" alt="image"
type defaultRemoteProvider struct { provider string endpoint string path string secretKeyring string } 作者考虑升级吗
签名计算bug
ConfigServerURL = http://apollo.meta/configsvc-dev 时, 使用token计算签名时,会把 pathwithquery部分的 /configsvc-dev 漏掉,导致签名失败, 建议在使用requestURI时,不要简单拼接,而是使用url.parse获取 data:image/s3,"s3://crabby-images/50663/50663badc1426ef1db4410e42ed88a09868b333c" alt="image"
依赖的github.com/bketelsen/crypt 0.0.4 (depend github.com/hashicorp/consul/api v1.1.0) 版本太低,存在 CWE-285/CWE-770/CWE-125/CWE-863/CWE-79安全漏洞。 HashiCorp Consul is vulnerable to privilege escalation due to the improper authorization of certificates that are being used for Raft requests. A remote...
chore(deps): bump github.com/bketelsen/crypt from from v0.0.4 to v0.0.5