You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This package includes a file fuzz/fuzz-fuzz.zip which includes binaries (sonar.exe, cover.exe). These files are detected as vulnerable by security scanners as they were compiled with Go 1.14.1.
I think this is file should not be committed into Git.
The text was updated successfully, but these errors were encountered:
Historically, Go exe files have been known to raise false vulnerabilities by scanners.
This code was added quite a while back and now there's native fuzzing available in the Go toolchain. It would be great if you want to revamp the entire fuzzing part - remove all the old code, and redo fuzzing using the new way.
Otherwise, I don't think there's a big downside in keeping them.
This package includes a file
fuzz/fuzz-fuzz.zip
which includes binaries (sonar.exe
,cover.exe
). These files are detected as vulnerable by security scanners as they were compiled with Go 1.14.1.I think this is file should not be committed into Git.
The text was updated successfully, but these errors were encountered: