Vulnerabilities (CVE)

Filtered by vendor Goreleaser Subscribe
Filtered by product Goreleaser
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-23840 1 Goreleaser 1 Goreleaser 2024-11-21 N/A 5.5 MEDIUM
GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a tap repository. `goreleaser release --debug` log shows secret values used in the in the custom publisher. This vulnerability is fixed in 1.24.0.