Skip to content

Release 1.9.0 available without tag (might be compromised/hijacked) #908

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
gaaf opened this issue Aug 20, 2024 · 7 comments
Closed

Release 1.9.0 available without tag (might be compromised/hijacked) #908

gaaf opened this issue Aug 20, 2024 · 7 comments

Comments

@gaaf
Copy link
Contributor

gaaf commented Aug 20, 2024

Hi,

I noticed that pkg.go.dev serves a version 1.9.0 of this package. On the github repo there's no such tag, the changelog doesn't mention a 1.9.0 version and the links on said page are dead.

I cannot determine if the served package is legitimate. Please either update the changelog and tag the appropriate commit or make sure pkg.go.dev doesn't serve an unauthorized version.

@dveeden
Copy link
Collaborator

dveeden commented Aug 21, 2024

Related: #906

@dveeden
Copy link
Collaborator

dveeden commented Aug 21, 2024

Looks like #907 is also related

@dveeden
Copy link
Collaborator

dveeden commented Aug 21, 2024

cc @atercattus

@atercattus
Copy link
Member

Yes, this is my mistake. I make a new tag 1.9 without checking that main branch is working. When I realized this, I removed the tag ASAP to avoid distributing unstable main. Unfortunately, pkg.go.dev already saw the new tag...

We are thinking about these fixes here #907

@lance6716
Copy link
Collaborator

I have recreated v1.9.0 https://github.com/go-mysql-org/go-mysql/tags let's see if it can overwrite the old tag

@lance6716
Copy link
Collaborator

I think I should create v1.9.1 https://go.dev/blog/go116-module-changes

a version cannot be modified after it is published

@lance6716
Copy link
Collaborator

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants