Debian Package Tracker
Register | Log in
Subscribe

golang-github-hashicorp-go-getter

download from a URL using a variety of protocols

Choose email to subscribe with

general
  • source: golang-github-hashicorp-go-getter (main)
  • version: 1.4.1-1
  • maintainer: Debian Go Packaging Team (archive) (DMD)
  • uploaders: Dmitry Smirnov [DMD]
  • arch: all
  • std-ver: 4.4.1
  • VCS: Git (Browse)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.4.1-1
  • oldstable: 1.4.1-1
versioned links
  • 1.4.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • golang-github-hashicorp-go-getter-dev
package is gone
This package is not in any development repository. This probably means that the package has been removed (or has been renamed). Thus the information here is of little interest ... the package is going to disappear unless someone takes it over and reintroduces it.
action needed
Debci reports failed tests high
  • unstable: pass (log)
    The tests ran in 0:01:42
    Last run: 2025-12-17T20:45:24.000Z
    Previous status: unknown

  • testing: pass (log)
    The tests ran in 0:01:46
    Last run: 2024-11-01T02:59:04.000Z
    Previous status: unknown

  • stable: fail (log)
    The tests ran in 0:00:15
    Last run: 2025-08-11T01:57:26.000Z
    Previous status: unknown

Created: 2025-08-11 Last update: 2026-02-03 07:31
8 security issues in sid high

There are 8 open security issues in sid.

8 important issues:
  • CVE-2023-0475: HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.
  • CVE-2024-3817: HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package.
  • CVE-2024-6257: HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.
  • CVE-2025-8959: HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959, is fixed in go-getter 1.7.9.
  • CVE-2022-26945: go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.
  • CVE-2022-30321: go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0.
  • CVE-2022-30322: go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP responses. Fixed in 1.6.1 and 2.1.0.
  • CVE-2022-30323: go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.
Created: 2022-07-04 Last update: 2025-09-08 01:32
7 security issues in trixie high

There are 7 open security issues in trixie.

7 important issues:
  • CVE-2023-0475: HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.
  • CVE-2024-3817: HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package.
  • CVE-2024-6257: HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.
  • CVE-2022-26945: go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.
  • CVE-2022-30321: go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0.
  • CVE-2022-30322: go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP responses. Fixed in 1.6.1 and 2.1.0.
  • CVE-2022-30323: go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.
Created: 2023-06-11 Last update: 2024-10-03 01:30
6 security issues in buster high

There are 6 open security issues in buster.

1 important issue:
  • CVE-2024-6257: HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.
5 issues postponed or untriaged:
  • CVE-2023-0475: (postponed; to be fixed through a stable update) HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.
  • CVE-2022-26945: (postponed; to be fixed through a stable update) go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.
  • CVE-2022-30321: (postponed; to be fixed through a stable update) go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0.
  • CVE-2022-30322: (postponed; to be fixed through a stable update) go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP responses. Fixed in 1.6.1 and 2.1.0.
  • CVE-2022-30323: (postponed; to be fixed through a stable update) go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.
Created: 2024-06-26 Last update: 2024-06-27 17:57
No known security issue in bookworm wishlist

There are 8 open security issues in bookworm.

8 ignored issues:
  • CVE-2023-0475: HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.
  • CVE-2024-3817: HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package.
  • CVE-2024-6257: HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.
  • CVE-2025-8959: HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959, is fixed in go-getter 1.7.9.
  • CVE-2022-26945: go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.
  • CVE-2022-30321: go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0.
  • CVE-2022-30322: go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP responses. Fixed in 1.6.1 and 2.1.0.
  • CVE-2022-30323: go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.
Created: 2023-06-10 Last update: 2026-01-20 23:03
news
[rss feed]
  • [2026-01-20] Removed 1.4.1-1 from unstable (Debian FTP Masters)
  • [2024-11-02] golang-github-hashicorp-go-getter REMOVED from testing (Debian testing watch)
  • [2020-01-12] golang-github-hashicorp-go-getter 1.4.1-1 MIGRATED to testing (Debian testing watch)
  • [2020-01-10] Accepted golang-github-hashicorp-go-getter 1.4.1-1 (source) into unstable (Dmitry Smirnov)
  • [2019-09-28] golang-github-hashicorp-go-getter 1.4.0-1 MIGRATED to testing (Debian testing watch)
  • [2019-09-26] Accepted golang-github-hashicorp-go-getter 1.4.0-1 (source) into unstable (Dmitry Smirnov)
  • [2016-10-14] golang-github-hashicorp-go-getter 0.0~git20160316.0.575ec4e-1 MIGRATED to testing (Debian testing watch)
  • [2016-10-12] golang-github-hashicorp-go-getter REMOVED from testing (Debian testing watch)
  • [2016-03-25] golang-github-hashicorp-go-getter 0.0~git20160316.0.575ec4e-1 MIGRATED to testing (Debian testing watch)
  • [2016-03-19] Accepted golang-github-hashicorp-go-getter 0.0~git20160316.0.575ec4e-1 (source all) into unstable, unstable (Dmitry Smirnov)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • buildd: logs
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debci

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing