Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/pkgsite: image in readme and privacy #43114

Closed
pierrre opened this issue Dec 10, 2020 · 2 comments
Closed

x/pkgsite: image in readme and privacy #43114

pierrre opened this issue Dec 10, 2020 · 2 comments
Labels
FrozenDueToAge NeedsInvestigation Someone must examine and confirm this is a valid issue and not a duplicate of an existing one. pkgsite

Comments

@pierrre
Copy link

pierrre commented Dec 10, 2020

If a readme includes images, they're showed directly on pkg.go.dev.
It could cause privacy/security issue:

  • the image could be used to track users (statistics/IP/etc...)
  • if the image is "malicious", and the web browser has a bug, it could crash it, or execute arbitrary code

We should probably have an image proxy (similar to what Github does).

I'm surprised nobody reported it already.
I haven't found any similar issue on the tracker.
Maybe I didn't search correctly.

@gopherbot gopherbot added this to the Unreleased milestone Dec 10, 2020
@jamalc jamalc added the NeedsInvestigation Someone must examine and confirm this is a valid issue and not a duplicate of an existing one. label Dec 10, 2020
@jamalc jamalc modified the milestones: Unreleased, pkgsite/unplanned Dec 10, 2020
@julieqiu
Copy link
Member

Closing this as a duplicate of #37128.

@pierrre
Copy link
Author

pierrre commented Dec 11, 2020

sorry for the duplicate, I couldn't find this other issue in my search.

@golang golang locked and limited conversation to collaborators Dec 11, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
FrozenDueToAge NeedsInvestigation Someone must examine and confirm this is a valid issue and not a duplicate of an existing one. pkgsite
Projects
None yet
Development

No branches or pull requests

4 participants