Bug#1040507: golang-1.21-go: downloads and runs binaries from the Internet without permission

2023-07-07 Thread Tianon Gravi
On Thu, 6 Jul 2023 at 14:39, brian m. carlson wrote: > Go 1.21 provides the `GOTOOLCHAIN` environment variable and associated > functionality[0]. As part of this code, if go.mod indicates that a > newer version of Go is required than the current toolchain supports, it > proceeds by default to

Bug#1040507: golang-1.21-go: downloads and runs binaries from the Internet without permission

2023-07-06 Thread brian m. carlson
Package: golang-1.21-go Version: 1.21~rc2-2 Severity: grave Tags: security Go 1.21 provides the `GOTOOLCHAIN` environment variable and associated functionality[0]. As part of this code, if go.mod indicates that a newer version of Go is required than the current toolchain supports, it proceeds by