Affected by GO-2026-6309
and 4 other vulnerabilities
GO-2026-6309: Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe in github.com/hatchet-dev/hatchet
GO-2026-6560: Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter in github.com/hatchet-dev/hatchet
GO-2026-6561: Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher in github.com/hatchet-dev/hatchet
GO-2026-6565: Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler in hatchet-dev/hatchet
GO-2026-6567: Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check in github.com/hatchet-dev/hatchet
type RandomTicker struct {
C chan time.Time// contains filtered or unexported fields
}
RandomTicker is similar to time.Ticker but ticks at random intervals between
the min and max duration values (stored internally as int64 nanosecond
counts).
NewRandomTicker returns a pointer to an initialized instance of the
RandomTicker. Min and max are durations of the shortest and longest allowed
ticks. Ticker will run in a goroutine until explicitly stopped.