Zstandard (RFC 8878) is well-positioned to replaced GZIP ([RFC 1952](https://datatracker.ietf.org/doc
The full firehose, with digest picks marked.
Everything our pipeline collected. Use the section tabs and filters to narrow — look for the In digest badge to see which stories actually made it into the newsletter.
Tekton Pipelines VolumeMount path restriction bypass via missing filepath.Clean in github.com/tektoncd/pipeline
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching in github.com/tektoncd/pipeline
Tekton Pipelines HTTP resolver denial of service via memory exhaustion in github.com/tektoncd/pipeline
Tekton Pipelines git resolver revision parameter argument injection in github.com/tektoncd/pipeline
Tekton Pipelines controller panic via long resolver name in TaskRun/PipelineRun in github.com/tektoncd/pipeline
Path traversal in Tekton Pipelines git resolver in github.com/tektoncd/pipeline
Tekton Pipelines git resolver leaks API token to user-controlled serverURL in github.com/tektoncd/pipeline
Proposal Details The flag package currently has Visit and VisitAll iterators, but unfortunately, the iterators don't return bool, so they aren't compa
The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, i
When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it
The /debug/vars endpoint in Dgraph Alpha discloses the administrator's authentication token without requiring authentication. This allows an unauthenticated remote attacker to obtain the token and gai
Proposal Details This is a meta-proposal. I propose that any change that merely adds a String or GoString method to an existing type, and makes only v

Remote - Solve complex security and platform engineering challenges that protect critical payment infrastructure at scale. THE PROJECT 📝 As a Senior Software Engineer, you will be engaged to delive
Hello, I'm Maneshwar. I'm building git-lrc, a Micro AI code reviewer that runs on every commit. It is...
Targeting Go 1.28 — Updated for status (adonovan): - [x] Scanner.Err analyzer implementation, enabled in gopls (https://go.dev/cl/730480) - [x] sql.Rows analyzer implemen
The Go cryptographic libraries are currently split between the standard library and the golang.org/x/crypto module. This document discusses the issues
Disclosure: I work at Synadia (the company behind NATS, which is a pure-Go project). Sharing because these are free and might be useful to Go folks working with messaging/streaming. We ran a set of ha

Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that coul
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that coul
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev
Gitea: Personal access token scope enforcement bypass on the repository home page ( ) discloses private repository contents in gitea.dev
Gitea Docker image: default lets any source IP impersonate any user via in code.gitea.io/gitea
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of 37698) in gitea.dev
Proposal Details There is a use case in proposal https://github.com/golang/go/issues/80434 for allowing callers to convert a raw socket address to a S
