fluxcd/flux2 软件分析报告

基础信息

项目名称:fluxcd/flux2

项目徽章:

Security Status

仓库地址:https://github.com/pterodactyl/panel

检测报告地址:https://www.murphysec.com/console/report/1717905882125828096/1717905894952009728

此报告由Murphysec提供

漏洞列表

暂无

缺陷组件

暂无

许可证风险

许可证类型 相关组件 许可证风险
MPL-2.0 13
MIT 77
BSD-3-Clause 48
Apache-2.0 118
CC-BY-SA-4.0 2
ISC 2
BSD-2-Clause 6
Unicode-DFS-2016 1

SBOM清单

组件名称 组件版本 是否直接依赖 仓库
github.com/hashicorp/go-multierror v1.1.1 间接依赖 go
github.com/gonvenience/term v1.0.2 间接依赖 go
golang.org/x/time v0.3.0 间接依赖 go
github.com/peterbourgon/diskv v2.0.1+incompatible 间接依赖 go
github.com/gorilla/mux v1.8.0 间接依赖 go
google.golang.org/protobuf v1.31.0 间接依赖 go
github.com/hashicorp/go-version v1.6.0 间接依赖 go
github.com/docker/docker v24.0.0+incompatible 间接依赖 go
github.com/fluxcd/pkg/runtime v0.42.0 直接依赖 go
github.com/sergi/go-diff v1.3.1 间接依赖 go
golang.org/x/net v0.17.0 间接依赖 go
github.com/fluxcd/pkg/tar v0.3.0 直接依赖 go
github.com/hashicorp/terraform-json v0.15.0 间接依赖 go
github.com/exponent-io/jsonpath v0.0.0-20210407135951-1de76d718b3f 间接依赖 go
github.com/ProtonMail/go-crypto v0.0.0-20230828082145-3c4c8a2d2371 直接依赖 go
github.com/imdario/mergo v0.3.15 间接依赖 go
github.com/json-iterator/go v1.1.12 间接依赖 go
google.golang.org/api v0.124.0 间接依赖 go
github.com/theckman/yacspin v0.13.12 直接依赖 go
github.com/docker/docker v23.0.3+incompatible 间接依赖 go
github.com/go-openapi/swag v0.22.3 间接依赖 go
github.com/sirupsen/logrus v1.9.3 间接依赖 go
github.com/spf13/pflag v1.0.5 直接依赖 go
github.com/vbatts/tar-split v0.11.3 间接依赖 go
github.com/Azure/go-autorest/logger v0.2.1 间接依赖 go
github.com/gogo/protobuf v1.3.2 间接依赖 go
golang.org/x/oauth2 v0.13.0 间接依赖 go
cloud.google.com/go/compute/metadata v0.2.3 间接依赖 go
github.com/rivo/uniseg v0.2.0 间接依赖 go
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 间接依赖 go
github.com/hashicorp/terraform-exec v0.18.1 直接依赖 go
github.com/onsi/gomega v1.27.10 直接依赖 go
github.com/fluxcd/pkg/oci v0.32.0 直接依赖 go
github.com/virtuald/go-ordered-json v0.0.0-20170621173500-b18e6e673d74 间接依赖 go
github.com/Azure/azure-event-hubs-go/v3 v3.6.1 直接依赖 go
github.com/emicklei/go-restful/v3 v3.10.0 间接依赖 go
github.com/go-git/go-billy/v5 v5.5.0 间接依赖 go
k8s.io/api v0.27.4 直接依赖 go
github.com/cloudflare/circl v1.3.3 间接依赖 go
github.com/go-openapi/jsonpointer v0.19.6 间接依赖 go
github.com/docker/libtrust v0.0.0-20150114040149-fa567046d9b1 间接依赖 go
github.com/fluxcd/pkg/ssa v0.32.0 直接依赖 go
github.com/docker/go-metrics v0.0.1 间接依赖 go
github.com/beorn7/perks v1.0.1 间接依赖 go
github.com/Azure/azure-sdk-for-go/sdk/internal v1.3.0 间接依赖 go
github.com/moby/spdystream v0.2.0 间接依赖 go
github.com/xlab/treeprint v1.1.0 间接依赖 go
github.com/inconshreveable/mousetrap v1.1.0 间接依赖 go
k8s.io/component-base v0.27.4 间接依赖 go
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 间接依赖 go
github.com/mattn/go-runewidth v0.0.13 间接依赖 go
k8s.io/kube-openapi v0.0.0-20230501164219-8b0f38b5fd1f 间接依赖 go
github.com/olekukonko/tablewriter v0.0.5 直接依赖 go
github.com/Azure/go-autorest/autorest/to v0.4.0 间接依赖 go
github.com/hashicorp/hc-install v0.5.0 间接依赖 go
github.com/Azure/go-autorest/autorest/date v0.3.0 间接依赖 go
github.com/klauspost/compress v1.16.0 间接依赖 go
k8s.io/kubectl v0.27.4 直接依赖 go
github.com/liggitt/tabwriter v0.0.0-20181228230101-89fcab3d43de 间接依赖 go
github.com/prometheus/common v0.42.0 间接依赖 go
cloud.google.com/go/iam v1.0.1 间接依赖 go
golang.org/x/oauth2 v0.5.0 间接依赖 go
github.com/go-git/go-git/v5 v5.9.0 直接依赖 go
github.com/fluxcd/test-infra/tftestenv v0.0.0-20230831142147-627bca8e7916 直接依赖 go
github.com/Azure/go-autorest v14.2.0+incompatible 间接依赖 go
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd 间接依赖 go
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 间接依赖 go
github.com/opencontainers/go-digest v1.0.0 间接依赖 go
gopkg.in/inf.v0 v0.9.1 间接依赖 go
github.com/fsnotify/fsnotify v1.6.0 间接依赖 go
github.com/hashicorp/golang-lru/arc/v2 v2.0.5 间接依赖 go
github.com/kevinburke/ssh_config v1.2.0 间接依赖 go
github.com/fluxcd/pkg/apis/event v0.5.2 直接依赖 go
github.com/xanzy/go-gitlab v0.93.1 间接依赖 go
github.com/gregjones/httpcache v0.0.0-20190611155906-901d90724c79 间接依赖 go
k8s.io/client-go v0.27.4 直接依赖 go
github.com/google/btree v1.1.2 间接依赖 go
github.com/opencontainers/image-spec v1.1.0-rc2 间接依赖 go
github.com/mailru/easyjson v0.7.7 间接依赖 go
k8s.io/apimachinery v0.27.4 直接依赖 go
github.com/fluxcd/pkg/git v0.14.0 直接依赖 go
github.com/davecgh/go-spew v1.1.1 间接依赖 go
github.com/Azure/go-amqp v1.0.0 间接依赖 go
github.com/Azure/go-autorest/autorest v0.11.28 间接依赖 go
github.com/prometheus/client_model v0.4.0 间接依赖 go
github.com/google/uuid v1.3.0 间接依赖 go
cloud.google.com/go v0.110.2 间接依赖 go
github.com/zclconf/go-cty v1.13.0 间接依赖 go
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.7.1 间接依赖 go
github.com/go-errors/errors v1.4.2 间接依赖 go
github.com/cespare/xxhash/v2 v2.2.0 间接依赖 go
github.com/mitchellh/go-wordwrap v1.0.1 间接依赖 go
github.com/whilp/git-urls v1.0.0 直接依赖 go
gopkg.in/yaml.v2 v2.4.0 间接依赖 go
github.com/google/gofuzz v1.2.0 间接依赖 go
github.com/fluxcd/kustomize-controller/api v1.1.1 直接依赖 go
github.com/mitchellh/mapstructure v1.5.0 间接依赖 go
github.com/spf13/cobra v1.7.0 直接依赖 go
github.com/fluxcd/pkg/apis/acl v0.1.0 间接依赖 go
github.com/go-logr/logr v1.2.4 直接依赖 go
github.com/mattn/go-isatty v0.0.19 间接依赖 go
github.com/fluxcd/pkg/apis/meta v1.1.2 直接依赖 go
github.com/mattn/go-shellwords v1.0.12 直接依赖 go
sigs.k8s.io/structured-merge-diff/v4 v4.2.3 间接依赖 go
github.com/fluxcd/pkg/git/gogit v0.14.0 直接依赖 go
github.com/fluxcd/pkg/version v0.2.2 直接依赖 go
github.com/mitchellh/hashstructure v1.1.0 间接依赖 go
sigs.k8s.io/structured-merge-diff/v4 v4.3.0 间接依赖 go
golang.org/x/tools v0.13.0 间接依赖 go
golang.org/x/sync v0.3.0 间接依赖 go
github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1 间接依赖 go
golang.org/x/term v0.13.0 直接依赖 go
github.com/skeema/knownhosts v1.2.0 间接依赖 go
github.com/fluxcd/helm-controller/api v0.36.2 直接依赖 go
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da 间接依赖 go
sigs.k8s.io/cli-utils v0.35.0 直接依赖 go
github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 间接依赖 go
github.com/gonvenience/wrap v1.1.2 间接依赖 go
sigs.k8s.io/controller-runtime v0.15.1 直接依赖 go
github.com/Azure/azure-amqp-common-go/v4 v4.2.0 间接依赖 go
github.com/jpillora/backoff v1.0.0 间接依赖 go
github.com/google/go-containerregistry v0.16.1 直接依赖 go
github.com/onsi/gomega v1.28.0 直接依赖 go
github.com/fluxcd/image-automation-controller/api v0.36.1 直接依赖 go
github.com/evanphx/json-patch/v5 v5.6.0 间接依赖 go
golang.org/x/crypto v0.14.0 直接依赖 go
github.com/acomagu/bufpipe v1.0.4 间接依赖 go
github.com/Azure/go-autorest/tracing v0.6.0 间接依赖 go
github.com/mattn/go-ciede2000 v0.0.0-20170301095244-782e8c62fec3 间接依赖 go
sigs.k8s.io/yaml v1.3.0 直接依赖 go
gopkg.in/warnings.v0 v0.1.2 间接依赖 go
github.com/manifoldco/promptui v0.9.0 直接依赖 go
google.golang.org/appengine v1.6.7 间接依赖 go
github.com/google/go-querystring v1.1.0 间接依赖 go
github.com/golang/protobuf v1.5.3 间接依赖 go
github.com/distribution/distribution/v3 v3.0.0-20230823142118-4f7424c8eb41 直接依赖 go
github.com/hashicorp/terraform-json v0.16.0 直接依赖 go
github.com/docker/distribution v2.8.2+incompatible 间接依赖 go
github.com/pmezard/go-difflib v1.0.0 间接依赖 go
github.com/xanzy/ssh-agent v0.3.3 间接依赖 go
go.uber.org/atomic v1.10.0 间接依赖 go
github.com/googleapis/enterprise-certificate-proxy v0.2.3 间接依赖 go
github.com/aws/aws-sdk-go-v2/internal/configsources v1.1.41 间接依赖 go
github.com/lucasb-eyer/go-colorful v1.2.0 直接依赖 go
github.com/google/gnostic v0.6.9 间接依赖 go
github.com/aws/aws-sdk-go-v2/internal/ini v1.3.42 间接依赖 go
github.com/mitchellh/go-ps v1.0.0 间接依赖 go
github.com/monochromegane/go-gitignore v0.0.0-20200626010858-205db1a8cc00 间接依赖 go
github.com/Microsoft/go-winio v0.6.1 间接依赖 go
github.com/opencontainers/image-spec v1.1.0-rc3 间接依赖 go
github.com/BurntSushi/toml v1.3.2 间接依赖 go
k8s.io/klog/v2 v2.100.1 直接依赖 go
sigs.k8s.io/kustomize/kyaml v0.14.2 直接依赖 go
github.com/Azure/go-autorest/autorest/validation v0.3.1 间接依赖 go
github.com/containerd/stargz-snapshotter/estargz v0.14.3 间接依赖 go
github.com/prometheus/client_golang v1.16.0 间接依赖 go
github.com/fluxcd/pkg/ssh v0.8.2 直接依赖 go
github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.3.1 间接依赖 go
github.com/gonvenience/ytbx v1.4.4 直接依赖 go
k8s.io/apiextensions-apiserver v0.27.4 直接依赖 go
github.com/docker/cli v23.0.1+incompatible 间接依赖 go
go.starlark.net v0.0.0-20221028183056-acb66ad56dd2 间接依赖 go
github.com/bshuster-repo/logrus-logstash-hook v1.0.0 间接依赖 go
github.com/russross/blackfriday/v2 v2.1.0 间接依赖 go
github.com/google/go-cmp v0.5.9 直接依赖 go
github.com/aws/aws-sdk-go-v2/service/ecr v1.19.5 间接依赖 go
github.com/aws/smithy-go v1.14.2 间接依赖 go
github.com/stretchr/testify v1.8.4 直接依赖 go
github.com/docker/go-events v0.0.0-20190806004212-e31b211e4f1c 间接依赖 go
github.com/aws/aws-sdk-go-v2 v1.21.0 间接依赖 go
github.com/kylelemons/godebug v1.1.0 间接依赖 go
golang.org/x/sys v0.13.0 间接依赖 go
github.com/Azure/azure-sdk-for-go v65.0.0+incompatible 间接依赖 go
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.15.5 间接依赖 go
github.com/fluxcd/source-controller/api v1.1.2 直接依赖 go
github.com/pkg/browser v0.0.0-20210911075715-681adbf594b8 间接依赖 go
github.com/texttheater/golang-levenshtein v1.0.1 间接依赖 go
github.com/google/go-containerregistry v0.14.0 直接依赖 go
github.com/mattn/go-colorable v0.1.12 间接依赖 go
github.com/hashicorp/golang-lru/v2 v2.0.5 间接依赖 go
dario.cat/mergo v1.0.0 间接依赖 go
github.com/docker/cli v24.0.0+incompatible 间接依赖 go
github.com/chai2010/gettext-go v1.0.2 间接依赖 go
github.com/hashicorp/go-retryablehttp v0.7.4 间接依赖 go
github.com/gonvenience/neat v1.3.12 间接依赖 go
sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd 间接依赖 go
github.com/emirpasic/gods v1.18.1 间接依赖 go
github.com/Azure/go-autorest/autorest/adal v0.9.21 间接依赖 go
github.com/fluxcd/pkg/sourceignore v0.3.5 直接依赖 go
github.com/phayes/freeport v0.0.0-20220201140144-74d24b5ae9f5 直接依赖 go
github.com/fluxcd/pkg/kustomize v1.3.4 直接依赖 go
github.com/josharian/intern v1.0.0 间接依赖 go
github.com/aws/aws-sdk-go-v2/credentials v1.13.35 间接依赖 go
github.com/cpuguy83/go-md2man/v2 v2.0.2 间接依赖 go
github.com/MakeNowJust/heredoc v1.0.0 间接依赖 go
golang.org/x/mod v0.12.0 间接依赖 go
github.com/klauspost/compress v1.16.5 间接依赖 go
github.com/aws/aws-sdk-go-v2/service/sts v1.21.5 间接依赖 go
github.com/moby/term v0.0.0-20221205130635-1aeaba878587 间接依赖 go
sigs.k8s.io/kustomize/api v0.13.4 直接依赖 go
github.com/cyphar/filepath-securejoin v0.2.4 直接依赖 go
github.com/hashicorp/hc-install v0.5.2 直接依赖 go
cloud.google.com/go/pubsub v1.31.0 直接依赖 go
github.com/AzureAD/microsoft-authentication-library-for-go v1.1.1 间接依赖 go
github.com/gonvenience/text v1.0.7 间接依赖 go
go.opencensus.io v0.24.0 间接依赖 go
github.com/hashicorp/errwrap v1.1.0 间接依赖 go
github.com/pjbgf/sha1cd v0.3.0 间接依赖 go
github.com/golang-jwt/jwt/v5 v5.0.0 间接依赖 go
github.com/hashicorp/errwrap v1.0.0 间接依赖 go
github.com/fluxcd/image-reflector-controller/api v0.30.0 直接依赖 go
github.com/gomodule/redigo v1.8.2 间接依赖 go
gomodules.xyz/jsonpatch/v2 v2.3.0 间接依赖 go
github.com/golang-jwt/jwt/v4 v4.4.2 间接依赖 go
google.golang.org/grpc v1.56.3 直接依赖 go
golang.org/x/oauth2 v0.8.0 间接依赖 go
github.com/google/go-github/v55 v55.0.0 间接依赖 go
k8s.io/utils v0.0.0-20230505201702-9f6742963106 间接依赖 go
github.com/google/s2a-go v0.1.4 间接依赖 go
github.com/Masterminds/semver/v3 v3.2.1 直接依赖 go
github.com/homeport/dyff v1.5.8 直接依赖 go
golang.org/x/text v0.13.0 直接依赖 go
github.com/apparentlymart/go-textseg/v13 v13.0.0 间接依赖 go
github.com/fluxcd/notification-controller/api v1.1.0 直接依赖 go
github.com/modern-go/reflect2 v1.0.2 间接依赖 go
github.com/aws/aws-sdk-go-v2/service/sso v1.13.5 间接依赖 go
github.com/microsoft/azure-devops-go-api/azuredevops v1.0.0-b5 直接依赖 go
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.9.35 间接依赖 go
github.com/sirupsen/logrus v1.9.0 间接依赖 go
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.13.11 间接依赖 go
github.com/vbatts/tar-split v0.11.2 间接依赖 go
github.com/gorilla/handlers v1.5.1 间接依赖 go
github.com/felixge/httpsnoop v1.0.3 间接依赖 go
github.com/hashicorp/go-cleanhttp v0.5.2 直接依赖 go
gopkg.in/yaml.v3 v3.0.1 间接依赖 go
github.com/aws/aws-sdk-go-v2/config v1.18.36 间接依赖 go
github.com/jmespath/go-jmespath v0.4.0 间接依赖 go
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.4.35 间接依赖 go
github.com/drone/envsubst v1.0.3 间接依赖 go
github.com/pkg/errors v0.9.1 间接依赖 go
google.golang.org/genproto v0.0.0-20230410155749-daa745c078e1 间接依赖 go
github.com/evanphx/json-patch v5.6.0+incompatible 间接依赖 go
github.com/fluxcd/pkg/apis/kustomize v1.1.1 间接依赖 go
github.com/go-openapi/jsonreference v0.20.1 间接依赖 go
github.com/fatih/color v1.13.0 间接依赖 go
github.com/devigned/tab v0.1.1 间接依赖 go
cloud.google.com/go/compute v1.19.1 间接依赖 go
github.com/gonvenience/bunt v1.3.5 直接依赖 go
go.uber.org/multierr v1.11.0 直接依赖 go
google.golang.org/protobuf v1.30.0 间接依赖 go
github.com/chzyer/readline v0.0.0-20180603132655-2972be24d48e 间接依赖 go
github.com/docker/docker-credential-helpers v0.7.0 间接依赖 go
github.com/Azure/azure-event-hubs-go/v3 v3.6.0 直接依赖 go
github.com/matttproud/golang_protobuf_extensions v1.0.4 间接依赖 go
github.com/fluxcd/go-git-providers v0.19.1 直接依赖 go
k8s.io/cli-runtime v0.27.4 直接依赖 go
github.com/googleapis/gax-go/v2 v2.9.1 间接依赖 go
github.com/prometheus/procfs v0.10.1 间接依赖 go
github.com/mitchellh/go-homedir v1.1.0 间接依赖 go
(0)
上一篇 2023年10月27日
下一篇 2023年10月27日

相关推荐

  • cbrauckmuller/helium 软件分析报告

    基础信息 项目名称:cbrauckmuller/helium 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1716594503016120320/1716594503079034880 此报告由Murphysec…

    软件分析 2023年10月24日
    0
  • blei-lab/edward 软件分析报告

    基础信息 项目名称:blei-lab/edward 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1727547266750697472/1727547266851360768 此报告由Murphysec提供 漏洞…

    软件分析 2023年11月23日
    0
  • asciimoo/wuzz 软件分析报告

    基础信息 项目名称:asciimoo/wuzz 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1727441108344463360/1727441108382212096 此报告由Murphysec提供 漏洞列表…

    软件分析 2023年11月23日
    0
  • fent/randexp.js 软件分析报告

    基础信息 项目名称:fent/randexp.js 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721193393954033664/1730927915761623040 此报告由Murphysec提供 漏洞…

    软件分析 2023年12月2日
    0
  • b2a3e8/jekyll-theme-console 软件分析报告

    基础信息 项目名称:b2a3e8/jekyll-theme-console 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1716202743759945728/1716202743801888768 此报告由Mu…

    软件分析 2023年10月23日
    0