Like of Finding Evil Go Packages (michenriksen.comβ¦)
Michael Henriksen has looked at popular Go packages to see how prevalent typosquatting for Dependency Confusion attacks is in Go ecosystem. Turns out, it’s not that bad but there are at least two widely used packages that you should double check.
Do you want to give me feedback about this article in private? Please send it to comments@zerokspot.com.
Alternatively, this website also supports Webmentions. If you write a post on a blog that supports this technique, I should get notified about your link π