Affected by GO-2024-3166
and 3 other vulnerabilities
GO-2024-3166: Incorrect delegation lookups can make go-tuf download the wrong artifact in github.com/theupdateframework/go-tuf
GO-2026-4348: Client DoS via malformed server response in github.com/theupdateframework/go-tuf
GO-2026-4349: Improper validattion of configured threshold for delegations in github.com/theupdateframework/go-tuf
GO-2026-4377: Path traversal in TAP 4 multirepo client allows arbitrary file write via repo names in github.com/theupdateframework/go-tuf
directory
Version:
v2.0.0
Opens a new window with list of versions in this module.
Published: Jul 16, 2024
License: Apache-2.0
Opens a new window with license information.
README
¶
Overview
The following CLIs are experimental replacements of the CLI tools provided by the go-tuf package:
Directories
¶
Click to show internal directories.
Click to hide internal directories.