5 ms·
Well, I do understand that the actual version used there is ambiguous. Probably the best would be to take the newest from go.sum. That’s what some scanners ar
by salmo 4y ago
Well, I do understand that the actual version used there is ambiguous.
Probably the best would be to take the newest from go.sum. That’s what some scanners are doing now.
Filed bugs with 2 vendors over this though.
- preseinger 4y agoThe newest from go.sum isn't reliably the version used in the dep graph. The only way to get that information reliably is via go list. Unfortunately.
- salmo 4y agoOh, you are totally right. I read that in the GitLab issue tracking their version of the problem and totally forgot that’s where they landed.
- kubanczyk 4y agoFor the curious it's: go list -m all
- smoyer 4y agoAlso don't forget that more than one version of a dependency might be compiled into your application!
- arccy 4y agonot true for go
- preseinger 4y agoOnly one major version. And go considers different major versions to be different dependencies.