VDB
Sign up
MEDIUM6.2

GHSA-f6mm-5fc7-3g3c

goreleaser shows environment by default

Quick fix

GHSA-f6mm-5fc7-3g3c — github.com/goreleaser/goreleaser: upgrade to the fixed version with the command below.

go get github.com/goreleaser/goreleaser@v1.26.1

Details

### Summary Since #4787 the log output is printed on the INFO level, while previously it was logged on DEBUG. This means if the `go build` output is non-empty, goreleaser leaks the environment.

### PoC * Create a Go project with dependencies, do not pull them yet (or run goreleaser later in a container, or delete `$GOPATH/pkg`). * Make sure to have secrets set in the environment * Make sure to not have `go mod tidy` in a before hook * Run `goreleaser release --clean` * Go prints lots of `go: downloading ...` lines, which triggers the "if output not empty, log it" line, which includes the environment.

### Impact Credentials and tokens are leaked.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/goreleaser/goreleaser
Introduced in: 1.26.0Fixed in: 1.26.1
Fixgo get github.com/goreleaser/goreleaser@v1.26.1

References