github.com/stacklok/minder
Software Supply Chain Security Platform
Activity
- Latest release
- 1mo ago
- Total releases
- 60
- Cadence
- ~10 days
- Last 12 months
- 7
Reach
- Stars
- 414
Details
- First release
- Sep 06, 2023
| Version | Released | |
|---|---|---|
v0.3.1
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.3.1
patch
Dependencies (118)
+ 110 more |
|
v0.3.0
minor
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.3.0
minor
Dependencies (118)
+ 110 more |
|
v0.2.2
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.2.2
patch
Dependencies (118)
+ 110 more |
|
v0.2.1
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.2.1
patch
Dependencies (118)
+ 110 more |
|
v0.2.0
minor
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.2.0
minor
Dependencies (118)
+ 110 more |
|
v0.1.2
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.1.2
patch
Dependencies (115)
+ 107 more |
|
v0.1.1
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.1.1
patch
Dependencies (115)
+ 107 more |
|
v0.1.0
minor
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.1.0
minor
Dependencies (113)
+ 105 more |
|
v0.0.89
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.89
patch
Dependencies (112)
+ 104 more |
|
v0.0.88
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.88
patch
Dependencies (112)
+ 104 more |
|
v0.0.87
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.87
patch
Dependencies (112)
+ 104 more |
|
v0.0.86
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.86
patch
Dependencies (112)
+ 104 more |
|
v0.0.85
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.85
patch
Dependencies (110)
+ 102 more |
|
v0.0.84
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.84
patch
Dependencies (110)
+ 102 more |
|
v0.0.83
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.83
patch
Dependencies (110)
+ 102 more |
|
v0.0.82
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.82
patch
Dependencies (110)
+ 102 more |
|
v0.0.81
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.81
patch
Dependencies (107)
+ 99 more |
|
v0.0.80
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.80
patch
Dependencies (107)
+ 99 more |
|
v0.0.79
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.79
patch
Dependencies (106)
+ 98 more |
|
v0.0.78
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.78
patch
Dependencies (106)
+ 98 more |
|
v0.0.77
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.77
patch
Dependencies (106)
+ 98 more |
|
v0.0.75
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.75
patch
Dependencies (106)
+ 98 more |
|
v0.0.74
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.74
patch
Dependencies (104)
+ 96 more |
|
v0.0.72
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.72
patch
Dependencies (104)
+ 96 more |
|
v0.0.69
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.69
patch
Dependencies (100)
+ 92 more |
|
v0.0.65
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.65
patch
Dependencies (98)
+ 90 more |
|
v0.0.64
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.64
patch
Dependencies (98)
+ 90 more |
|
v0.0.61
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.61
patch
Dependencies (95)
+ 87 more |
|
v0.0.59
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.59
patch
Dependencies (90)
+ 82 more |
|
v0.0.58
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.58
patch
Dependencies (90)
+ 82 more |
|
v0.0.57
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.57
patch
Dependencies (89)
+ 81 more |
|
v0.0.56
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.56
patch
Dependencies (87)
+ 79 more |
|
v0.0.55
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.55
patch
Dependencies (87)
+ 79 more |
|
v0.0.54
patch
1 CVE
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev |
v0.0.54
patch
Dependencies (87)
+ 79 more |
|
v0.0.51
patch
2 CVEs
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-37904
GO-2024-2934
GHSA-hpcg-xjq5-g666
Jun 28, 2024
Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Fixed in
0.0.52
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.0.51
patch
Dependencies (84)
+ 76 more |
|
v0.0.47
patch
6 CVEs
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-37904
GO-2024-2934
GHSA-hpcg-xjq5-g666
Jun 28, 2024
Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Fixed in
0.0.52
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35194
GO-2024-2871
GHSA-crgc-2583-rw27
Jun 05, 2024
Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Fixed in
0.0.50
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35238
GO-2024-2885
GHSA-8fmj-33gw-g7pw
Jun 05, 2024
Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Fixed in
0.0.51
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35185
GO-2024-2864
GHSA-fjw8-3gp8-4cvx
May 20, 2024
Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Fixed in
0.0.49
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34084
GO-2024-2821
GHSA-9c5w-9q3f-3hv7
May 10, 2024
Denial of Service from untrusted requests in github.com/stacklok/minder HandleGithubWebhook is susceptible to a denial of service attack from an untrusted HTTP request. An untrusted request can cause the server to allocate large amounts of memory resulting in a denial of service. Fixed in
0.0.48
References
Updated May 20, 2024 · Source: OSV.dev |
v0.0.47
patch
Dependencies (77)
+ 69 more |
|
v0.0.39
patch
7 CVEs
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-37904
GO-2024-2934
GHSA-hpcg-xjq5-g666
Jun 28, 2024
Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Fixed in
0.0.52
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35194
GO-2024-2871
GHSA-crgc-2583-rw27
Jun 05, 2024
Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Fixed in
0.0.50
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35238
GO-2024-2885
GHSA-8fmj-33gw-g7pw
Jun 05, 2024
Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Fixed in
0.0.51
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-31455
GO-2024-2701
GHSA-ggp5-28x4-xcj9
Jun 04, 2024
Minder GetRepositoryByName data leak in github.com/stacklok/minder Minder GetRepositoryByName data leak in github.com/stacklok/minder Fixed in
0.0.40
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35185
GO-2024-2864
GHSA-fjw8-3gp8-4cvx
May 20, 2024
Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Fixed in
0.0.49
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34084
GO-2024-2821
GHSA-9c5w-9q3f-3hv7
May 10, 2024
Denial of Service from untrusted requests in github.com/stacklok/minder HandleGithubWebhook is susceptible to a denial of service attack from an untrusted HTTP request. An untrusted request can cause the server to allocate large amounts of memory resulting in a denial of service. Fixed in
0.0.48
References
Updated May 20, 2024 · Source: OSV.dev |
v0.0.39
patch
Dependencies (76)
+ 68 more |
|
v0.0.38
patch
6 CVEs
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-37904
GO-2024-2934
GHSA-hpcg-xjq5-g666
Jun 28, 2024
Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Fixed in
0.0.52
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35194
GO-2024-2871
GHSA-crgc-2583-rw27
Jun 05, 2024
Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Fixed in
0.0.50
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35238
GO-2024-2885
GHSA-8fmj-33gw-g7pw
Jun 05, 2024
Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Fixed in
0.0.51
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35185
GO-2024-2864
GHSA-fjw8-3gp8-4cvx
May 20, 2024
Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Fixed in
0.0.49
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34084
GO-2024-2821
GHSA-9c5w-9q3f-3hv7
May 10, 2024
Denial of Service from untrusted requests in github.com/stacklok/minder HandleGithubWebhook is susceptible to a denial of service attack from an untrusted HTTP request. An untrusted request can cause the server to allocate large amounts of memory resulting in a denial of service. Fixed in
0.0.48
References
Updated May 20, 2024 · Source: OSV.dev |
v0.0.38
patch
Dependencies (76)
+ 68 more |
|
v0.0.37
patch
6 CVEs
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-37904
GO-2024-2934
GHSA-hpcg-xjq5-g666
Jun 28, 2024
Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Fixed in
0.0.52
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35194
GO-2024-2871
GHSA-crgc-2583-rw27
Jun 05, 2024
Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Fixed in
0.0.50
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35238
GO-2024-2885
GHSA-8fmj-33gw-g7pw
Jun 05, 2024
Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Fixed in
0.0.51
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35185
GO-2024-2864
GHSA-fjw8-3gp8-4cvx
May 20, 2024
Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Fixed in
0.0.49
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34084
GO-2024-2821
GHSA-9c5w-9q3f-3hv7
May 10, 2024
Denial of Service from untrusted requests in github.com/stacklok/minder HandleGithubWebhook is susceptible to a denial of service attack from an untrusted HTTP request. An untrusted request can cause the server to allocate large amounts of memory resulting in a denial of service. Fixed in
0.0.48
References
Updated May 20, 2024 · Source: OSV.dev |
v0.0.37
patch
Dependencies (76)
+ 68 more |
|
v0.0.34
patch
6 CVEs
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-37904
GO-2024-2934
GHSA-hpcg-xjq5-g666
Jun 28, 2024
Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Fixed in
0.0.52
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35194
GO-2024-2871
GHSA-crgc-2583-rw27
Jun 05, 2024
Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Fixed in
0.0.50
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35238
GO-2024-2885
GHSA-8fmj-33gw-g7pw
Jun 05, 2024
Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Fixed in
0.0.51
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35185
GO-2024-2864
GHSA-fjw8-3gp8-4cvx
May 20, 2024
Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Fixed in
0.0.49
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34084
GO-2024-2821
GHSA-9c5w-9q3f-3hv7
May 10, 2024
Denial of Service from untrusted requests in github.com/stacklok/minder HandleGithubWebhook is susceptible to a denial of service attack from an untrusted HTTP request. An untrusted request can cause the server to allocate large amounts of memory resulting in a denial of service. Fixed in
0.0.48
References
Updated May 20, 2024 · Source: OSV.dev |
v0.0.34
patch
Dependencies (73)
+ 65 more |
|
v0.0.26
patch
7 CVEs
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-37904
GO-2024-2934
GHSA-hpcg-xjq5-g666
Jun 28, 2024
Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Fixed in
0.0.52
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35194
GO-2024-2871
GHSA-crgc-2583-rw27
Jun 05, 2024
Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Fixed in
0.0.50
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35238
GO-2024-2885
GHSA-8fmj-33gw-g7pw
Jun 05, 2024
Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Fixed in
0.0.51
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35185
GO-2024-2864
GHSA-fjw8-3gp8-4cvx
May 20, 2024
Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Fixed in
0.0.49
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34084
GO-2024-2821
GHSA-9c5w-9q3f-3hv7
May 10, 2024
Denial of Service from untrusted requests in github.com/stacklok/minder HandleGithubWebhook is susceptible to a denial of service attack from an untrusted HTTP request. An untrusted request can cause the server to allocate large amounts of memory resulting in a denial of service. Fixed in
0.0.48
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2024-27916
GO-2024-2608
GHSA-v627-69v2-xx37
Mar 11, 2024
Minder access control bypass in github.com/stacklok/minder A Minder user can use the endpoints to access any repository in the DB, irrespective of who owns the repo and any permissions that user may have. The DB query used checks by repo owner, repo name and provider name (which is always "github"). These query values are not distinct for the particular user, as long as the user has valid credentials and a provider, they can set the repo owner/name to any value they want and the server will return information on this repo. DeleteRepositoryByName uses the same query and a user can delete another user's repo using this technique. The GetArtifactByName endpoint also uses this DB query. Fixed in
0.0.33
References Updated May 20, 2024 · Source: OSV.dev |
v0.0.26
patch
Dependencies (71)
+ 63 more |
|
v0.0.25
patch
7 CVEs
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-37904
GO-2024-2934
GHSA-hpcg-xjq5-g666
Jun 28, 2024
Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Fixed in
0.0.52
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35194
GO-2024-2871
GHSA-crgc-2583-rw27
Jun 05, 2024
Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Fixed in
0.0.50
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35238
GO-2024-2885
GHSA-8fmj-33gw-g7pw
Jun 05, 2024
Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Fixed in
0.0.51
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35185
GO-2024-2864
GHSA-fjw8-3gp8-4cvx
May 20, 2024
Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Fixed in
0.0.49
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34084
GO-2024-2821
GHSA-9c5w-9q3f-3hv7
May 10, 2024
Denial of Service from untrusted requests in github.com/stacklok/minder HandleGithubWebhook is susceptible to a denial of service attack from an untrusted HTTP request. An untrusted request can cause the server to allocate large amounts of memory resulting in a denial of service. Fixed in
0.0.48
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2024-27916
GO-2024-2608
GHSA-v627-69v2-xx37
Mar 11, 2024
Minder access control bypass in github.com/stacklok/minder A Minder user can use the endpoints to access any repository in the DB, irrespective of who owns the repo and any permissions that user may have. The DB query used checks by repo owner, repo name and provider name (which is always "github"). These query values are not distinct for the particular user, as long as the user has valid credentials and a provider, they can set the repo owner/name to any value they want and the server will return information on this repo. DeleteRepositoryByName uses the same query and a user can delete another user's repo using this technique. The GetArtifactByName endpoint also uses this DB query. Fixed in
0.0.33
References Updated May 20, 2024 · Source: OSV.dev |
v0.0.25
patch
Dependencies (71)
+ 63 more |
|
v0.0.24
patch
7 CVEs
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-37904
GO-2024-2934
GHSA-hpcg-xjq5-g666
Jun 28, 2024
Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Fixed in
0.0.52
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35194
GO-2024-2871
GHSA-crgc-2583-rw27
Jun 05, 2024
Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Fixed in
0.0.50
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35238
GO-2024-2885
GHSA-8fmj-33gw-g7pw
Jun 05, 2024
Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Fixed in
0.0.51
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35185
GO-2024-2864
GHSA-fjw8-3gp8-4cvx
May 20, 2024
Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Fixed in
0.0.49
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34084
GO-2024-2821
GHSA-9c5w-9q3f-3hv7
May 10, 2024
Denial of Service from untrusted requests in github.com/stacklok/minder HandleGithubWebhook is susceptible to a denial of service attack from an untrusted HTTP request. An untrusted request can cause the server to allocate large amounts of memory resulting in a denial of service. Fixed in
0.0.48
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2024-27916
GO-2024-2608
GHSA-v627-69v2-xx37
Mar 11, 2024
Minder access control bypass in github.com/stacklok/minder A Minder user can use the endpoints to access any repository in the DB, irrespective of who owns the repo and any permissions that user may have. The DB query used checks by repo owner, repo name and provider name (which is always "github"). These query values are not distinct for the particular user, as long as the user has valid credentials and a provider, they can set the repo owner/name to any value they want and the server will return information on this repo. DeleteRepositoryByName uses the same query and a user can delete another user's repo using this technique. The GetArtifactByName endpoint also uses this DB query. Fixed in
0.0.33
References Updated May 20, 2024 · Source: OSV.dev |
v0.0.24
patch
Dependencies (71)
+ 63 more |
|
v0.0.23
patch
7 CVEs
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-37904
GO-2024-2934
GHSA-hpcg-xjq5-g666
Jun 28, 2024
Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Fixed in
0.0.52
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35194
GO-2024-2871
GHSA-crgc-2583-rw27
Jun 05, 2024
Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Fixed in
0.0.50
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35238
GO-2024-2885
GHSA-8fmj-33gw-g7pw
Jun 05, 2024
Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Fixed in
0.0.51
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35185
GO-2024-2864
GHSA-fjw8-3gp8-4cvx
May 20, 2024
Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Fixed in
0.0.49
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34084
GO-2024-2821
GHSA-9c5w-9q3f-3hv7
May 10, 2024
Denial of Service from untrusted requests in github.com/stacklok/minder HandleGithubWebhook is susceptible to a denial of service attack from an untrusted HTTP request. An untrusted request can cause the server to allocate large amounts of memory resulting in a denial of service. Fixed in
0.0.48
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2024-27916
GO-2024-2608
GHSA-v627-69v2-xx37
Mar 11, 2024
Minder access control bypass in github.com/stacklok/minder A Minder user can use the endpoints to access any repository in the DB, irrespective of who owns the repo and any permissions that user may have. The DB query used checks by repo owner, repo name and provider name (which is always "github"). These query values are not distinct for the particular user, as long as the user has valid credentials and a provider, they can set the repo owner/name to any value they want and the server will return information on this repo. DeleteRepositoryByName uses the same query and a user can delete another user's repo using this technique. The GetArtifactByName endpoint also uses this DB query. Fixed in
0.0.33
References Updated May 20, 2024 · Source: OSV.dev |
v0.0.23
patch
Dependencies (72)
+ 64 more |
|
v0.0.22
patch
7 CVEs
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-37904
GO-2024-2934
GHSA-hpcg-xjq5-g666
Jun 28, 2024
Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Fixed in
0.0.52
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35194
GO-2024-2871
GHSA-crgc-2583-rw27
Jun 05, 2024
Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Fixed in
0.0.50
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35238
GO-2024-2885
GHSA-8fmj-33gw-g7pw
Jun 05, 2024
Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Fixed in
0.0.51
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35185
GO-2024-2864
GHSA-fjw8-3gp8-4cvx
May 20, 2024
Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Fixed in
0.0.49
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34084
GO-2024-2821
GHSA-9c5w-9q3f-3hv7
May 10, 2024
Denial of Service from untrusted requests in github.com/stacklok/minder HandleGithubWebhook is susceptible to a denial of service attack from an untrusted HTTP request. An untrusted request can cause the server to allocate large amounts of memory resulting in a denial of service. Fixed in
0.0.48
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2024-27916
GO-2024-2608
GHSA-v627-69v2-xx37
Mar 11, 2024
Minder access control bypass in github.com/stacklok/minder A Minder user can use the endpoints to access any repository in the DB, irrespective of who owns the repo and any permissions that user may have. The DB query used checks by repo owner, repo name and provider name (which is always "github"). These query values are not distinct for the particular user, as long as the user has valid credentials and a provider, they can set the repo owner/name to any value they want and the server will return information on this repo. DeleteRepositoryByName uses the same query and a user can delete another user's repo using this technique. The GetArtifactByName endpoint also uses this DB query. Fixed in
0.0.33
References Updated May 20, 2024 · Source: OSV.dev |
v0.0.22
patch
Dependencies (73)
+ 65 more |
|
v0.0.21
patch
7 CVEs
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-37904
GO-2024-2934
GHSA-hpcg-xjq5-g666
Jun 28, 2024
Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Fixed in
0.0.52
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35194
GO-2024-2871
GHSA-crgc-2583-rw27
Jun 05, 2024
Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Fixed in
0.0.50
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35238
GO-2024-2885
GHSA-8fmj-33gw-g7pw
Jun 05, 2024
Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Fixed in
0.0.51
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35185
GO-2024-2864
GHSA-fjw8-3gp8-4cvx
May 20, 2024
Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Fixed in
0.0.49
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34084
GO-2024-2821
GHSA-9c5w-9q3f-3hv7
May 10, 2024
Denial of Service from untrusted requests in github.com/stacklok/minder HandleGithubWebhook is susceptible to a denial of service attack from an untrusted HTTP request. An untrusted request can cause the server to allocate large amounts of memory resulting in a denial of service. Fixed in
0.0.48
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2024-27916
GO-2024-2608
GHSA-v627-69v2-xx37
Mar 11, 2024
Minder access control bypass in github.com/stacklok/minder A Minder user can use the endpoints to access any repository in the DB, irrespective of who owns the repo and any permissions that user may have. The DB query used checks by repo owner, repo name and provider name (which is always "github"). These query values are not distinct for the particular user, as long as the user has valid credentials and a provider, they can set the repo owner/name to any value they want and the server will return information on this repo. DeleteRepositoryByName uses the same query and a user can delete another user's repo using this technique. The GetArtifactByName endpoint also uses this DB query. Fixed in
0.0.33
References Updated May 20, 2024 · Source: OSV.dev |
v0.0.21
patch
Dependencies (72)
+ 64 more |
|
v0.0.19
patch
7 CVEs
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-37904
GO-2024-2934
GHSA-hpcg-xjq5-g666
Jun 28, 2024
Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Fixed in
0.0.52
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35194
GO-2024-2871
GHSA-crgc-2583-rw27
Jun 05, 2024
Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Fixed in
0.0.50
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35238
GO-2024-2885
GHSA-8fmj-33gw-g7pw
Jun 05, 2024
Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Fixed in
0.0.51
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35185
GO-2024-2864
GHSA-fjw8-3gp8-4cvx
May 20, 2024
Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Fixed in
0.0.49
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34084
GO-2024-2821
GHSA-9c5w-9q3f-3hv7
May 10, 2024
Denial of Service from untrusted requests in github.com/stacklok/minder HandleGithubWebhook is susceptible to a denial of service attack from an untrusted HTTP request. An untrusted request can cause the server to allocate large amounts of memory resulting in a denial of service. Fixed in
0.0.48
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2024-27916
GO-2024-2608
GHSA-v627-69v2-xx37
Mar 11, 2024
Minder access control bypass in github.com/stacklok/minder A Minder user can use the endpoints to access any repository in the DB, irrespective of who owns the repo and any permissions that user may have. The DB query used checks by repo owner, repo name and provider name (which is always "github"). These query values are not distinct for the particular user, as long as the user has valid credentials and a provider, they can set the repo owner/name to any value they want and the server will return information on this repo. DeleteRepositoryByName uses the same query and a user can delete another user's repo using this technique. The GetArtifactByName endpoint also uses this DB query. Fixed in
0.0.33
References Updated May 20, 2024 · Source: OSV.dev |
v0.0.19
patch
Dependencies (73)
+ 65 more |
|
v0.0.18
patch
7 CVEs
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-37904
GO-2024-2934
GHSA-hpcg-xjq5-g666
Jun 28, 2024
Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Fixed in
0.0.52
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35194
GO-2024-2871
GHSA-crgc-2583-rw27
Jun 05, 2024
Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Fixed in
0.0.50
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35238
GO-2024-2885
GHSA-8fmj-33gw-g7pw
Jun 05, 2024
Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Fixed in
0.0.51
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35185
GO-2024-2864
GHSA-fjw8-3gp8-4cvx
May 20, 2024
Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Fixed in
0.0.49
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34084
GO-2024-2821
GHSA-9c5w-9q3f-3hv7
May 10, 2024
Denial of Service from untrusted requests in github.com/stacklok/minder HandleGithubWebhook is susceptible to a denial of service attack from an untrusted HTTP request. An untrusted request can cause the server to allocate large amounts of memory resulting in a denial of service. Fixed in
0.0.48
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2024-27916
GO-2024-2608
GHSA-v627-69v2-xx37
Mar 11, 2024
Minder access control bypass in github.com/stacklok/minder A Minder user can use the endpoints to access any repository in the DB, irrespective of who owns the repo and any permissions that user may have. The DB query used checks by repo owner, repo name and provider name (which is always "github"). These query values are not distinct for the particular user, as long as the user has valid credentials and a provider, they can set the repo owner/name to any value they want and the server will return information on this repo. DeleteRepositoryByName uses the same query and a user can delete another user's repo using this technique. The GetArtifactByName endpoint also uses this DB query. Fixed in
0.0.33
References Updated May 20, 2024 · Source: OSV.dev |
v0.0.18
patch
Dependencies (71)
+ 63 more |
|
v0.0.17
patch
7 CVEs
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-37904
GO-2024-2934
GHSA-hpcg-xjq5-g666
Jun 28, 2024
Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Fixed in
0.0.52
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35194
GO-2024-2871
GHSA-crgc-2583-rw27
Jun 05, 2024
Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Fixed in
0.0.50
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35238
GO-2024-2885
GHSA-8fmj-33gw-g7pw
Jun 05, 2024
Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Fixed in
0.0.51
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35185
GO-2024-2864
GHSA-fjw8-3gp8-4cvx
May 20, 2024
Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Fixed in
0.0.49
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34084
GO-2024-2821
GHSA-9c5w-9q3f-3hv7
May 10, 2024
Denial of Service from untrusted requests in github.com/stacklok/minder HandleGithubWebhook is susceptible to a denial of service attack from an untrusted HTTP request. An untrusted request can cause the server to allocate large amounts of memory resulting in a denial of service. Fixed in
0.0.48
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2024-27916
GO-2024-2608
GHSA-v627-69v2-xx37
Mar 11, 2024
Minder access control bypass in github.com/stacklok/minder A Minder user can use the endpoints to access any repository in the DB, irrespective of who owns the repo and any permissions that user may have. The DB query used checks by repo owner, repo name and provider name (which is always "github"). These query values are not distinct for the particular user, as long as the user has valid credentials and a provider, they can set the repo owner/name to any value they want and the server will return information on this repo. DeleteRepositoryByName uses the same query and a user can delete another user's repo using this technique. The GetArtifactByName endpoint also uses this DB query. Fixed in
0.0.33
References Updated May 20, 2024 · Source: OSV.dev |
v0.0.17
patch
Dependencies (71)
+ 63 more |
|
v0.0.16
patch
7 CVEs
CVE-2024-27093
GO-2024-2582
GHSA-q6h8-4j2v-pjg4
Jun 28, 2024
Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder Minder trusts client-provided mapping from repo name to upstream ID in github.com/stacklok/minder. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/stacklok/minder before v0.20240226.1425. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-37904
GO-2024-2934
GHSA-hpcg-xjq5-g666
Jun 28, 2024
Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Minder affected by denial of service from maliciously configured Git repository in github.com/stacklok/minder Fixed in
0.0.52
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35194
GO-2024-2871
GHSA-crgc-2583-rw27
Jun 05, 2024
Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Stacklok Minder vulnerable to denial of service from maliciously crafted templates in github.com/stacklok/minder Fixed in
0.0.50
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35238
GO-2024-2885
GHSA-8fmj-33gw-g7pw
Jun 05, 2024
Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Denial of service of Minder Server from maliciously crafted GitHub attestations in github.com/stacklok/minder Fixed in
0.0.51
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-35185
GO-2024-2864
GHSA-fjw8-3gp8-4cvx
May 20, 2024
Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Denial of service of Minder Server with attacker-controlled REST endpoint in github.com/stacklok/minder Fixed in
0.0.49
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34084
GO-2024-2821
GHSA-9c5w-9q3f-3hv7
May 10, 2024
Denial of Service from untrusted requests in github.com/stacklok/minder HandleGithubWebhook is susceptible to a denial of service attack from an untrusted HTTP request. An untrusted request can cause the server to allocate large amounts of memory resulting in a denial of service. Fixed in
0.0.48
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2024-27916
GO-2024-2608
GHSA-v627-69v2-xx37
Mar 11, 2024
Minder access control bypass in github.com/stacklok/minder A Minder user can use the endpoints to access any repository in the DB, irrespective of who owns the repo and any permissions that user may have. The DB query used checks by repo owner, repo name and provider name (which is always "github"). These query values are not distinct for the particular user, as long as the user has valid credentials and a provider, they can set the repo owner/name to any value they want and the server will return information on this repo. DeleteRepositoryByName uses the same query and a user can delete another user's repo using this technique. The GetArtifactByName endpoint also uses this DB query. Fixed in
0.0.33
References Updated May 20, 2024 · Source: OSV.dev |
v0.0.16
patch
Dependencies (70)
+ 62 more |