Affected by GO-2024-2582
and 4 other vulnerabilities
GO-2024-2582: Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder
GO-2024-2864: Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder
GO-2024-2871: Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder
GO-2024-2885: Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder
GO-2024-2934: Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder
package
Version:
v0.0.11
Opens a new window with list of versions in this module.
Published: Nov 4, 2023
License: Apache-2.0
Opens a new window with license information.
Imports: 9
Opens a new window with list of imports.
Imported by: 0
Opens a new window with list of known importers.
Documentation
¶
Package eval provides necessary interfaces and implementations for evaluating
rules.
NewRuleEvaluator creates a new rule data evaluator
Source Files
¶
Directories
¶
Package jq provides the jq profile evaluator
|
Package jq provides the jq profile evaluator |
Package pr_actions contains shared code to take on PRs
|
Package pr_actions contains shared code to take on PRs |
Package rego provides the rego rule evaluator
|
Package rego provides the rego rule evaluator |
Package trusty provides an evaluator that uses the trusty API
|
Package trusty provides an evaluator that uses the trusty API |
Package vulncheck provides the vulnerability check evaluator
|
Package vulncheck provides the vulnerability check evaluator |
Click to show internal directories.
Click to hide internal directories.