Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sum mismatch on v0.10.2 #8

Closed
iaburton opened this issue Aug 1, 2023 · 2 comments
Closed

Sum mismatch on v0.10.2 #8

iaburton opened this issue Aug 1, 2023 · 2 comments
Labels
bug Something isn't working

Comments

@iaburton
Copy link

iaburton commented Aug 1, 2023

Hello!

First, thank you for creating this generic-fork of the GoDS repo, I've been using it with success for the past month or so.

That said, my CICD system caches the Go mod/sum information, that way the data doesn't need to be pulled each time from the origin but also in case of a malicious replacement of a version of a package.

It seems like there may have been a change or replacement of v0.10.2 sometime in the last month or two?

github.com/ugurcsen/[email protected]: verifying module: checksum mismatch
	downloaded: h1:LeNa5QEDBRqZik4hvrbikzcyPjQk+ZZ3WL4F9j5QQKg=
	sum.golang.org: h1:dE/4oQEeO/oMVcWwcVeJhboxYJ0WVIbVVjOGJ32xL90=

SECURITY ERROR
This download does NOT match the one reported by the checksum server.
The bits may have been replaced on the origin server, or an attacker may
have intercepted the download attempt.

For more information, see 'go help module-auth'.

I found what looked like an accidental v0.10.3 release on deps.dev (the open source information link from the pkg.go.dev website)
https://deps.dev/go/github.com%2Fugurcsen%2Fgods-generic/v0.10.2/versions

There also seem to be a small number of updates on master. In order to correct this issue would it be possible to release another small version bump, perhaps v0.10.4 to correct the mismatch issue with 0.10.2?

Thank you!

@ugurcsen
Copy link
Owner

I release v0.10.4. Can you approve it is fixed?

@ugurcsen ugurcsen added the bug Something isn't working label Aug 16, 2023
@iaburton
Copy link
Author

Yes sir, it appears that releases fixes it. Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants