Skip to content

Package advisories

Go

173advisory rows139advisories115packagesRSSas of the 2026-09-07 snapshot

An advisory is the GHSA entry a Dependabot alert links to; GitHub-reviewed only. One row is one change to one package: 16 fixed-in version changed, 157 package added later.

No rate: 35,259 advisories were compared across every ecosystem together, and the analysis carries no count of how many were Go, so nothing here divides one number by the other.

Kind of change

157 counted rows in this one change · showing 101 to 150 · newest advisory first

One change, in full: Package added to advisory: 102 packages named as affected in go. The same change, 157 rows across 124 advisories. Back to go

Changes to GitHub-reviewed advisories naming a package in go. Each row gives the kind of change and the advisory it happened to. Where the same change was made to several advisories or packages at once, one row stands for all of them, says how many, and opens to every one. Then the ecosystem and package, what the advisory said beside what it says now, GitHub's severity level, and the date the advisory was published.
Package, The package the change names, or where one row stands for the same change across several packages, how many.Kind of changeAdvisory, The advisory id, or where one row stands for the same change made to several advisories, how many it stands for. An advisory id links to GitHub, and a CVE id is shown beside it where the advisory names one.What changedSeverity, GitHub's severity level for the advisory as it stands today: low, moderate, high or critical. Where one row stands for advisories at more than one level, it says how many levels, never one of them.Advisory published, The date the advisory was published. Every lag on this source is measured from it, and it is a third clock beside the CVE catalog's publication date and the date CISA added an entry to KEV. Two kinds of change also carry a date of their own: a withdrawal states its own timestamp, and a changed fix version is dated by reading back through the dated saves of the advisory file until the one where the version first reached the value it has today. A package added and a severity changed leave no commit of their own to date, so for those the date of the change is not recorded at all. That is absence, never same-day.
github.com/1panel-dev/1panelPackage added to advisoryGHSA-p9xf-74xh-mhw5CVE-2023-37477not named as affected when the advisory was published, now names github.com/1panel-dev/1panelhigh2023-07-18
github.com/zinclabs/zincPackage added to advisoryGHSA-4fgv-8448-gf82CVE-2022-32171not named as affected when the advisory was published, now names github.com/zinclabs/zincmoderate2023-07-06
github.com/zinclabs/zincPackage added to advisoryGHSA-7j6x-42mm-p7jmCVE-2022-32172not named as affected when the advisory was published, now names github.com/zinclabs/zincmoderate2023-07-06
github.com/hjson/hjson-go/v4Package added to advisoryGHSA-5wfc-hjrc-gq87CVE-2023-34620not named as affected when the advisory was published, now names github.com/hjson/hjson-go/v4high2023-06-14
github.com/rancher/rancherPackage added to advisoryGHSA-p976-h52c-26p6CVE-2023-22647not named as affected when the advisory was published, now names github.com/rancher/ranchercritical2023-06-06
github.com/rancher/rancherPackage added to advisoryGHSA-46v3-ggjg-qq3xCVE-2022-43760not named as affected when the advisory was published, now names github.com/rancher/ranchermoderate2023-06-06
github.com/ipld/go-codec-dagpbPackage added to advisoryGHSA-967g-cjx4-h7j6not named as affected when the advisory was published, now names github.com/ipld/go-codec-dagpbhigh2022-12-28
github.com/go-yaml/yamlPackage added to advisoryGHSA-r88r-gmrh-7j83CVE-2021-4235not named as affected when the advisory was published, now names github.com/go-yaml/yamlmoderate2022-12-28
aahframe.workPackage added to advisoryGHSA-vp56-r7qv-783vCVE-2020-36559not named as affected when the advisory was published, now names aahframe.workhigh2022-12-28
code.sajari.com/docconvPackage added to advisoryGHSA-qvx2-59g8-8hphCVE-2022-4741not named as affected when the advisory was published, now names code.sajari.com/docconvmoderate2022-12-25
code.sajari.com/docconvPackage added to advisoryGHSA-6m4h-hfpp-x8cxCVE-2022-4643not named as affected when the advisory was published, now names code.sajari.com/docconvcritical2022-12-22
tailscale.comPackage added to advisoryGHSA-vqp6-rc3h-83cpCVE-2022-41924not named as affected when the advisory was published, now names tailscale.comcritical2022-11-21
github.com/russellhaering/goxmldsigPackage added to advisoryGHSA-prjq-f4q3-fvfrCVE-2020-7731not named as affected when the advisory was published, now names github.com/russellhaering/goxmldsighigh2022-11-15
github.com/docker/dockerPackage added to advisoryGHSA-vp35-85q5-9f25not named as affected when the advisory was published, now names github.com/docker/dockerlow2022-11-11
github.com/russellhaering/gosaml2Package added to advisoryGHSA-mqqv-chpx-vq25CVE-2020-7711not named as affected when the advisory was published, now names github.com/russellhaering/gosaml2high2022-10-07
github.com/cloudwego/hertzPackage added to advisoryGHSA-c9qr-f6c8-rgxfCVE-2022-40082not named as affected when the advisory was published, now names github.com/cloudwego/hertzhigh2022-09-29
github.com/mattermost/mattermost-server/v6Package added to advisoryGHSA-m7w4-q5vg-5xfpCVE-2022-3257not named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v6moderate2022-09-25
github.com/docker/dockerPackage added to advisoryGHSA-rc4r-wh2q-q6c4CVE-2022-36109not named as affected when the advisory was published, now names github.com/docker/dockermoderate2022-09-16
github.com/matrix-org/gomatrixserverlibPackage added to advisoryGHSA-grvv-h2f9-7v9cCVE-2022-36009not named as affected when the advisory was published, now names github.com/matrix-org/gomatrixserverlibmoderate2022-08-30
github.com/hashicorp/consul-templatePackage added to advisoryGHSA-8449-7gc2-pwrpCVE-2022-38149not named as affected when the advisory was published, now names github.com/hashicorp/consul-templatehigh2022-08-18
github.com/ipfs/go-ipfsPackage added to advisoryGHSA-f2gr-7299-487hnot named as affected when the advisory was published, now names github.com/ipfs/go-ipfsmoderate2022-07-06
github.com/biscuit-auth/biscuit-goPackage added to advisoryGHSA-75rw-34q6-72crCVE-2022-31053not named as affected when the advisory was published, now names github.com/biscuit-auth/biscuit-gocritical2022-06-17
github.com/astaxie/beegoPackage added to advisoryGHSA-hf4p-4j9r-3cvxCVE-2019-16355not named as affected when the advisory was published, now names github.com/astaxie/beegomoderate2022-05-24
github.com/mattermost/mattermost-server/v5Package added to advisoryGHSA-j2h2-cvwh-cr64CVE-2020-14457not named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v5moderate2022-05-24
k8s.io/apiextensions-apiserverPackage added to advisoryGHSA-fp37-c92q-4pwqCVE-2019-11247not named as affected when the advisory was published, now names k8s.io/apiextensions-apiserverhigh2022-05-24
github.com/docker/dockerPackage added to advisoryGHSA-v2cv-wwxq-qq97CVE-2019-14271not named as affected when the advisory was published, now names github.com/docker/dockercritical2022-05-24
github.com/rs/corsPackage added to advisoryGHSA-927h-x4qj-r242CVE-2018-20744not named as affected when the advisory was published, now names github.com/rs/corsmoderate2022-05-14
github.com/containers/psgoPackage added to advisoryGHSA-66vw-v2x9-hw75CVE-2022-1227not named as affected when the advisory was published, now names github.com/containers/psgohigh2022-04-30
github.com/opencontainers/selinuxPackage added to advisoryGHSA-fgv8-vj5c-2ppqCVE-2019-16884not named as affected when the advisory was published, now names github.com/opencontainers/selinuxhigh2022-02-22
k8s.io/client-goPackage added to advisoryGHSA-2575-pghm-6qqxCVE-2019-11244not named as affected when the advisory was published, now names k8s.io/client-gomoderate2022-02-15
k8s.io/kubernetesPackage added to advisoryGHSA-34jx-wx69-9x8vCVE-2019-1002101not named as affected when the advisory was published, now names k8s.io/kubernetesmoderate2022-02-15
k8s.io/apiserverPackage added to advisoryGHSA-82hx-w2r5-c2wqCVE-2020-8552not named as affected when the advisory was published, now names k8s.io/apiservermoderate2022-02-15
github.com/docker/dockerPackage added to advisoryGHSA-8fvr-5rqf-3wwhCVE-2015-3630not named as affected when the advisory was published, now names github.com/docker/dockerhigh2022-02-15
k8s.io/kubernetesPackage added to advisoryGHSA-jp32-vmm6-3vf5CVE-2015-5305not named as affected when the advisory was published, now names k8s.io/kubernetesmoderate2022-02-15
github.com/projectcalico/calicoPackage added to advisoryGHSA-pf59-j7c2-rh6xCVE-2020-13597not named as affected when the advisory was published, now names github.com/projectcalico/calicomoderate2022-02-15
k8s.io/kubernetesPackage added to advisoryGHSA-qhm4-jxv7-j9pqCVE-2020-8551not named as affected when the advisory was published, now names k8s.io/kubernetesmoderate2022-02-15
github.com/docker/dockerPackage added to advisoryGHSA-v4h8-794j-g8mmCVE-2015-3631not named as affected when the advisory was published, now names github.com/docker/dockermoderate2022-02-15
k8s.io/kubernetesPackage added to advisoryGHSA-wqv3-8cm6-h6wgCVE-2020-8558not named as affected when the advisory was published, now names k8s.io/kuberneteshigh2022-02-15
k8s.io/kubernetesPackage added to advisoryGHSA-x6mj-w4jf-jmgwCVE-2020-8555not named as affected when the advisory was published, now names k8s.io/kubernetesmoderate2022-02-15
github.com/containous/traefik/v2Package added to advisoryGHSA-6qq8-5wq3-86rpCVE-2020-15129not named as affected when the advisory was published, now names github.com/containous/traefik/v2moderate2022-02-11
github.com/containous/traefik/v2/pkg/apiPackage added to advisoryGHSA-6qq8-5wq3-86rpCVE-2020-15129not named as affected when the advisory was published, now names github.com/containous/traefik/v2/pkg/apimoderate2022-02-11
github.com/keycloak/keycloak-gatekeeperPackage added to advisoryGHSA-jh6m-3pqw-242hCVE-2020-14359not named as affected when the advisory was published, now names github.com/keycloak/keycloak-gatekeeperhigh2022-02-09
github.com/russellhaering/goxmldsigPackage added to advisoryGHSA-m9hp-7r99-94h5CVE-2020-26290not named as affected when the advisory was published, now names github.com/russellhaering/goxmldsigcritical2021-12-20
github.com/go-yaml/yamlPackage added to advisoryGHSA-wxc4-f4m6-wwqvCVE-2019-11254not named as affected when the advisory was published, now names github.com/go-yaml/yamlmoderate2021-12-20
github.com/traefik/traefikPackage added to advisoryGHSA-7h6j-2268-fhcmCVE-2020-9321not named as affected when the advisory was published, now names github.com/traefik/traefikmoderate2021-09-02
istio.io/istioPackage added to advisoryGHSA-7774-7vr3-cc8jCVE-2021-39155not named as affected when the advisory was published, now names istio.io/istiohigh2021-08-30
github.com/argoproj/argo-cdPackage added to advisoryGHSA-h8jc-jmrf-9h8fCVE-2020-8828not named as affected when the advisory was published, now names github.com/argoproj/argo-cdhigh2021-07-26
github.com/holiman/uint256Package added to advisoryGHSA-jm5c-rv3w-w83mCVE-2020-26242not named as affected when the advisory was published, now names github.com/holiman/uint256moderate2021-06-29
github.com/gogits/gogsPackage added to advisoryGHSA-mr6h-chqp-p9g2CVE-2014-8681not named as affected when the advisory was published, now names github.com/gogits/gogsmoderate2021-06-29
golang.org/x/cryptoPackage added to advisoryGHSA-cjjc-xp8v-855wCVE-2020-7919not named as affected when the advisory was published, now names golang.org/x/cryptohigh2021-06-23

Every change counted from this source is on this page, so an advisory with no row here had no change of that kind. No finding here is not an all clear. It means this check found nothing in the history it can see, not that nothing happened.

A grouped row is the same change, repeated: where one change was made to many packages or advisories, the advisory column says how many it stands for and opens to every one. The change is identical; it was not necessarily made in one act.

A fixed-in version is compared within one release branch: an advisory listing a fix for 4.1.x and another for 4.2.x states two, and taking the highest version across the package would report a newly added branch as though an existing branch's fix had changed.

19 more advisories that name a package in go had the severity changed, or the whole advisory withdrawn. None of it is counted in any figure above. Open to read it.

A severity level and a withdrawal belong to the whole advisory. The advisory database records neither against a package, so neither can be attributed to an ecosystem. These 19 rows are here for one reason: the same advisory also names a package in go in the table above. The other 3,161 of the 3,180 cannot be placed in an ecosystem at all.

Severity changes and withdrawals recorded against advisories that also name a package in go. These rows name no ecosystem of their own and are not counted in this page's ecosystem figures.
Kind of changeAdvisoryWhat changedSeverityAdvisory published
Advisory severity changedGHSA-cj55-gc7m-wvcqCVE-2024-45258stated at publication HIGH, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.moderate2024-08-26
Advisory severity changedGHSA-rpcc-p8xm-rc6pCVE-2024-3056stated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.high2024-08-02
Advisory severity changedGHSA-869c-j7wc-8jqvCVE-2019-25211stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.critical2024-06-29
Advisory withdrawnGHSA-vfxf-76hv-v4w4withdrawn 2024-01-23high2024-01-03
Advisory severity changedGHSA-3f2q-6294-fmq5CVE-2023-46402stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2023-11-18
Advisory severity changedGHSA-j7hp-h8jx-5pprCVE-2023-4863stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2023-09-12
Advisory severity changedGHSA-5wfc-hjrc-gq87CVE-2023-34620stated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.high2023-06-14
Advisory severity changedGHSA-46v3-ggjg-qq3xCVE-2022-43760stated at publication HIGH, now states MODERATEA CVSS version was added; the existing vectors stayed the same.moderate2023-06-06
Advisory severity changedGHSA-r88r-gmrh-7j83CVE-2021-4235stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.moderate2022-12-28
Advisory severity changedGHSA-vp56-r7qv-783vCVE-2020-36559stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2022-12-28
Advisory withdrawnGHSA-967g-cjx4-h7j6withdrawn 2026-01-23high2022-12-28
Advisory severity changedGHSA-qx32-f6g6-fcfrCVE-2022-31259stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.critical2022-05-22
Advisory severity changedGHSA-hp87-p4gw-j4gqCVE-2022-28948stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2022-05-20
Advisory severity changedGHSA-pf59-j7c2-rh6xCVE-2020-13597stated at publication LOW, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.moderate2022-02-15
Advisory severity changedGHSA-qhm4-jxv7-j9pqCVE-2020-8551stated at publication LOW, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.moderate2022-02-15
Advisory severity changedGHSA-x6mj-w4jf-jmgwCVE-2020-8555stated at publication LOW, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.moderate2022-02-15
Advisory withdrawnGHSA-gq5r-cc4w-g8xfwithdrawn 2024-05-20high2021-06-23
Advisory severity changedGHSA-vj3f-3286-r4pfCVE-2014-9356stated at publication HIGH, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.moderate2021-05-18
Advisory withdrawnGHSA-2v6x-frw8-7r7fCVE-2019-17110withdrawn 2024-01-23moderate2021-05-18

Data sources and quality

Every figure on this page counts rows keyed to a GitHub advisory, naming an ecosystem and a package; none counts CVE records or is added to the record counts elsewhere on this site. Rows, advisories and packages are three different numbers, never added.

Not checked: GitHub-reviewed advisories only. An advisory GitHub never reviewed, and an ecosystem it does not review, produce no row at all, so an ecosystem missing from these figures is not evidence that its advisories held.

How advisories are compared, in full →

Advisory data from the GitHub Advisory Database, used under CC-BY-4.0. Not affiliated with or endorsed by GitHub.

Shipped snapshot computed 2026-09-07 from catalog commit f3250c735415. Real findings, not live ones: records amended since are not reflected. A later fix version is evidence that the record changed, not evidence that the first fix was incomplete.