huacnlee/gobackup 软件分析报告

基础信息

项目名称:huacnlee/gobackup

项目徽章:

Security Status

仓库地址:https://github.com/pterodactyl/panel

检测报告地址:https://www.murphysec.com/console/report/1718680299349082112/1718680299386830848

此报告由Murphysec提供

漏洞列表

漏洞名称 漏洞类型 MPS编号 CVE编号 漏洞等级
低危
Google protobuf 缓冲区错误漏洞 越界读取 MPS-2023-2917 CVE-2023-24535 高危
Gin 安全漏洞 下载代码缺少完整性检查 MPS-2023-9711 CVE-2023-29401 中危
PostCSS 安全漏洞 注入 MPS-y3tx-jzms CVE-2023-44270 中危

缺陷组件

组件名称 版本 最小修复版本 依赖关系 修复建议
google.golang.org/protobuf v1.29.0 1.29.1 间接依赖 建议修复
postcss 8.4.21 8.4.31 间接依赖 可选修复
github.com/gin-gonic/gin v1.9.0 1.9.1 直接依赖 可选修复
golang.org/x/net v0.8.0 0.17.0 间接依赖 可选修复

许可证风险

许可证类型 相关组件 许可证风险
MIT 197
BSD-3-Clause 25
Apache-2.0 28
MPL-2.0 5
CC-BY-4.0 1
ISC 10
BSD-2-Clause 4
Apache 2.0 1

SBOM清单

组件名称 组件版本 是否直接依赖 仓库
util-deprecate 1.0.2 间接依赖 npm
@swc/core-darwin-arm64 1.3.40 直接依赖 npm
rc-rate 2.10.0 间接依赖 npm
github.com/spf13/viper v1.14.0 直接依赖 go
github.com/studio-b12/gowebdav v0.0.0-20221109171924-60ec5ad56012 直接依赖 go
camelcase-css 2.0.1 间接依赖 npm
github.com/kr/fs v0.1.0 间接依赖 go
minimist 1.2.8 间接依赖 npm
github.com/Azure/azure-sdk-for-go/sdk/storage/azblob v0.6.1 直接依赖 go
github.com/robfig/cron/v3 v3.0.1 间接依赖 go
tailwindcss 3.2.7 直接依赖 npm
picomatch 2.3.1 间接依赖 npm
defined 1.0.1 间接依赖 npm
rc-progress 3.4.1 间接依赖 npm
github.com/fatih/color v1.14.1 直接依赖 go
github.com/kylelemons/godebug v1.1.0 间接依赖 go
compute-scroll-into-view 3.0.0 间接依赖 npm
@babel/runtime 7.21.0 间接依赖 npm
node-releases 2.0.10 间接依赖 npm
postcss-load-config 3.1.4 间接依赖 npm
postcss 8.4.21 间接依赖 npm
google.golang.org/protobuf v1.29.0 间接依赖 go
@rc-component/portal 1.1.0 间接依赖 npm
github.com/Azure/azure-sdk-for-go/sdk/internal v1.0.1 间接依赖 go
rc-virtual-list 3.4.13 间接依赖 npm
github.com/sevlyar/go-daemon v0.1.6 直接依赖 go
cloud.google.com/go/compute v1.12.1 间接依赖 go
color-name 1.1.4 间接依赖 npm
fill-range 7.0.1 间接依赖 npm
@ant-design/react-slick 1.0.0 间接依赖 npm
github.com/hashicorp/errwrap v1.0.0 间接依赖 go
@esbuild/freebsd-arm64 0.16.17 直接依赖 npm
cloud.google.com/go/compute/metadata v0.2.1 间接依赖 go
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd 间接依赖 go
github.com/spf13/cast v1.5.0 间接依赖 go
lilconfig 2.1.0 间接依赖 npm
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 直接依赖 go
micromatch 4.0.5 间接依赖 npm
readdirp 3.6.0 间接依赖 npm
github.com/longbridgeapp/assert v1.1.0 直接依赖 go
rc-textarea 1.0.1 间接依赖 npm
github.com/twitchyliquid64/golang-asm v0.15.1 间接依赖 go
react-router 6.11.2 间接依赖 npm
fraction.js 4.2.0 间接依赖 npm
mitt 1.2.0 间接依赖 npm
@esbuild/linux-ppc64 0.16.17 直接依赖 npm
arg 5.0.2 间接依赖 npm
github.com/go-playground/validator/v10 v10.11.2 间接依赖 go
caniuse-lite 1.0.30001465 间接依赖 npm
@nodelib/fs.scandir 2.1.5 间接依赖 npm
rc-picker 3.3.3 间接依赖 npm
github.com/stretchr/testify v1.8.2 间接依赖 go
react-router-dom 6.9.0 直接依赖 npm
github.com/xrash/smetrics v0.0.0-20201216005158-039620a65673 间接依赖 go
@esbuild/darwin-arm64 0.16.17 直接依赖 npm
rc-steps 6.0.0 间接依赖 npm
github.com/go-playground/universal-translator v0.18.1 间接依赖 go
github.com/hashicorp/go-multierror v1.1.1 间接依赖 go
vite 4.1.5 直接依赖 npm
@esbuild/linux-loong64 0.16.17 直接依赖 npm
golang.org/x/oauth2 v0.0.0-20221014153046-6fdb5e3db783 直接依赖 go
golang.org/x/arch v0.3.0 间接依赖 go
github.com/goccy/go-json v0.10.1 间接依赖 go
@esbuild/android-arm64 0.16.17 直接依赖 npm
@rc-component/mini-decimal 1.0.1 间接依赖 npm
prop-types 15.8.1 间接依赖 npm
rc-field-form 1.28.0 间接依赖 npm
github.com/rivo/uniseg v0.2.0 间接依赖 go
throttle-debounce 5.0.0 间接依赖 npm
@esbuild/netbsd-x64 0.16.17 直接依赖 npm
run-parallel 1.2.0 间接依赖 npm
filesize 10.0.6 直接依赖 npm
@swc/core-win32-ia32-msvc 1.3.40 直接依赖 npm
github.com/VividCortex/ewma v1.2.0 间接依赖 go
@swc/core-win32-arm64-msvc 1.3.40 直接依赖 npm
merge2 1.4.1 间接依赖 npm
filesize 10.0.7 直接依赖 npm
@types/whatwg-streams 0.0.7 间接依赖 npm
@esbuild/win32-x64 0.16.17 直接依赖 npm
scroll-into-view-if-needed 3.0.6 间接依赖 npm
@types/node 18.15.3 直接依赖 npm
update-browserslist-db 1.0.10 间接依赖 npm
copy-to-clipboard 3.3.3 间接依赖 npm
@swc/core 1.3.40 间接依赖 npm
@esbuild/win32-arm64 0.16.17 直接依赖 npm
github.com/pelletier/go-toml v1.9.5 间接依赖 go
@esbuild/openbsd-x64 0.16.17 直接依赖 npm
dlv 1.1.3 间接依赖 npm
github.com/bramvdbogaerde/go-scp v1.2.0 直接依赖 go
object-assign 4.1.1 间接依赖 npm
golang.org/x/sys v0.6.0 间接依赖 go
rc-select 14.3.0 间接依赖 npm
github.com/modern-go/reflect2 v1.0.2 间接依赖 go
esbuild 0.16.17 间接依赖 npm
electron-to-chromium 1.4.328 间接依赖 npm
function-bind 1.1.1 间接依赖 npm
@esbuild/linux-x64 0.16.17 直接依赖 npm
@nodelib/fs.walk 1.2.8 间接依赖 npm
rollup 3.19.1 间接依赖 npm
normalize-path 3.0.0 间接依赖 npm
react 18.2.0 直接依赖 npm
react-lazylog 4.5.3 直接依赖 npm
rc-slider 10.1.1 间接依赖 npm
binary-extensions 2.2.0 间接依赖 npm
postcss-value-parser 4.2.0 间接依赖 npm
postcss-selector-parser 6.0.11 间接依赖 npm
fetch-readablestream 0.2.0 间接依赖 npm
github.com/AzureAD/microsoft-authentication-library-for-go v0.7.0 间接依赖 go
golang.org/x/net v0.8.0 间接依赖 go
golang.org/x/crypto v0.7.0 直接依赖 go
cloud.google.com/go/iam v0.5.0 间接依赖 go
github.com/gin-contrib/sse v0.1.0 间接依赖 go
github.com/googleapis/enterprise-certificate-proxy v0.2.0 间接依赖 go
immutable 4.3.0 间接依赖 npm
react-dom 18.2.0 直接依赖 npm
rc-notification 5.0.3 间接依赖 npm
@swc/core-linux-x64-musl 1.3.40 直接依赖 npm
@ant-design/cssinjs 1.6.1 间接依赖 npm
escalade 3.1.1 间接依赖 npm
rc-motion 2.6.3 间接依赖 npm
@esbuild/win32-ia32 0.16.17 直接依赖 npm
github.com/gin-gonic/gin v1.9.0 直接依赖 go
postcss-js 4.0.1 间接依赖 npm
rc-tabs 12.5.10 间接依赖 npm
toggle-selection 1.0.6 间接依赖 npm
glob-parent 5.1.2 间接依赖 npm
@esbuild/android-x64 0.16.17 直接依赖 npm
@types/scheduler 0.16.2 间接依赖 npm
@ant-design/icons 5.0.1 间接依赖 npm
detective 5.2.1 间接依赖 npm
github.com/gin-contrib/static v0.0.1 直接依赖 go
object-hash 3.0.0 间接依赖 npm
reusify 1.0.4 间接依赖 npm
antd 5.3.1 直接依赖 npm
github.com/mitchellh/mapstructure v1.5.0 间接依赖 go
@swc/core-linux-arm64-gnu 1.3.40 直接依赖 npm
github.com/json-iterator/go v1.1.12 间接依赖 go
github.com/fsnotify/fsnotify v1.6.0 直接依赖 go
github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.2.0 直接依赖 go
rc-drawer 6.1.3 间接依赖 npm
read-cache 1.0.0 间接依赖 npm
rc-segmented 2.1.2 间接依赖 npm
rc-tooltip 6.0.1 间接依赖 npm
golang.org/x/text v0.8.0 间接依赖 go
github.com/pmezard/go-difflib v1.0.0 间接依赖 go
google.golang.org/api v0.102.0 直接依赖 go
react-router 6.9.0 间接依赖 npm
@esbuild/linux-s390x 0.16.17 直接依赖 npm
github.com/chenzhuoyu/base64x v0.0.0-20221115062448-fe3a3abad311 间接依赖 go
csstype 3.1.1 间接依赖 npm
rc-collapse 3.5.2 间接依赖 npm
js-tokens 4.0.0 间接依赖 npm
github.com/stoicperlman/fls v0.0.0-20171222144224-f073b7a01081 直接依赖 go
github.com/jlaffaye/ftp v0.1.0 直接依赖 go
github.com/spf13/afero v1.9.3 间接依赖 go
string-convert 0.2.1 间接依赖 npm
rc-checkbox 2.3.2 间接依赖 npm
chokidar 3.5.3 间接依赖 npm
@nodelib/fs.stat 2.0.5 间接依赖 npm
github.com/joho/godotenv v1.4.0 直接依赖 go
dom-align 1.12.4 间接依赖 npm
is-binary-path 2.1.0 间接依赖 npm
github.com/googleapis/gax-go/v2 v2.6.0 间接依赖 go
go.opencensus.io v0.23.0 间接依赖 go
braces 3.0.2 间接依赖 npm
@ctrl/tinycolor 3.6.0 间接依赖 npm
@esbuild/linux-ia32 0.16.17 直接依赖 npm
dayjs 1.11.7 间接依赖 npm
to-regex-range 5.0.1 间接依赖 npm
supports-preserve-symlinks-flag 1.0.0 间接依赖 npm
async-validator 4.2.5 间接依赖 npm
cssesc 3.0.0 间接依赖 npm
@ant-design/icons-svg 4.2.1 间接依赖 npm
github.com/leodido/go-urn v1.2.2 间接依赖 go
gopkg.in/ini.v1 v1.67.0 间接依赖 go
@vitejs/plugin-react-swc 3.2.0 直接依赖 npm
google.golang.org/genproto v0.0.0-20221024183307-1bc688fe9f3e 间接依赖 go
react-is 16.13.1 间接依赖 npm
gopkg.in/yaml.v2 v2.4.0 间接依赖 go
quick-lru 5.1.1 间接依赖 npm
normalize-range 0.1.2 间接依赖 npm
github.com/kardianos/osext v0.0.0-20190222173326-2bc1f35cddc0 间接依赖 go
rc-tree 5.7.2 间接依赖 npm
rc-dialog 9.0.2 间接依赖 npm
github.com/go-co-op/gocron v1.18.0 直接依赖 go
@esbuild/android-arm 0.16.17 直接依赖 npm
source-map-js 1.0.2 间接依赖 npm
stylis 4.1.3 间接依赖 npm
@types/prop-types 15.7.5 间接依赖 npm
@mattiasbuelens/web-streams-polyfill 0.2.1 间接依赖 npm
rc-image 5.15.2 间接依赖 npm
github.com/klauspost/cpuid/v2 v2.2.4 间接依赖 go
resize-observer-polyfill 1.5.1 间接依赖 npm
loose-envify 1.4.0 间接依赖 npm
rc-cascader 3.9.1 间接依赖 npm
github.com/spf13/pflag v1.0.5 间接依赖 go
rc-mentions 2.1.0 间接依赖 npm
@esbuild/linux-arm64 0.16.17 直接依赖 npm
react-virtualized 9.22.3 直接依赖 npm
browserslist 4.21.5 间接依赖 npm
@esbuild/darwin-x64 0.16.17 直接依赖 npm
github.com/aws/aws-sdk-go v1.34.0 直接依赖 go
acorn-walk 7.2.0 间接依赖 npm
@esbuild/freebsd-x64 0.16.17 直接依赖 npm
cloud.google.com/go/storage v1.28.0 直接依赖 go
google.golang.org/grpc v1.50.1 间接依赖 go
@types/react 18.0.28 直接依赖 npm
github.com/hako/durafmt v0.0.0-20210608085754-5c1018a4e16b 直接依赖 go
github.com/go-playground/locales v0.14.1 间接依赖 go
github.com/bytedance/sonic v1.8.4 间接依赖 go
rc-align 4.0.15 间接依赖 npm
rc-trigger 5.3.4 间接依赖 npm
rc-overflow 1.2.8 间接依赖 npm
scheduler 0.23.0 间接依赖 npm
autoprefixer 10.4.14 直接依赖 npm
@rc-component/context 1.3.0 间接依赖 npm
github.com/golang-jwt/jwt/v4 v4.4.2 间接依赖 go
postcss-import 14.1.0 间接依赖 npm
@esbuild/linux-riscv64 0.16.17 直接依赖 npm
github.com/google/go-cmp v0.5.9 间接依赖 go
@swc/core-win32-x64-msvc 1.3.40 直接依赖 npm
github.com/jmespath/go-jmespath v0.3.0 间接依赖 go
github.com/mattn/go-colorable v0.1.13 间接依赖 go
pify 2.3.0 间接依赖 npm
rc-resize-observer 1.3.1 间接依赖 npm
rc-input 0.2.2 间接依赖 npm
resolve 1.22.1 间接依赖 npm
github.com/magiconair/properties v1.8.7 间接依赖 go
nanoid 3.3.4 间接依赖 npm
@esbuild/linux-arm 0.16.17 直接依赖 npm
github.com/davecgh/go-spew v1.1.1 间接依赖 go
sass 1.59.2 直接依赖 npm
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.1.4 间接依赖 go
rc-menu 9.8.2 间接依赖 npm
@emotion/unitless 0.7.5 间接依赖 npm
github.com/urfave/cli/v2 v2.23.6 直接依赖 go
dom-helpers 5.2.1 间接依赖 npm
@esbuild/sunos-x64 0.16.17 直接依赖 npm
github.com/subosito/gotenv v1.4.1 间接依赖 go
immutable 3.8.2 间接依赖 npm
rc-util 5.28.0 间接依赖 npm
gopkg.in/yaml.v3 v3.0.1 间接依赖 go
is-extglob 2.1.1 间接依赖 npm
is-core-module 2.11.0 间接依赖 npm
fastq 1.15.0 间接依赖 npm
lodash 4.17.21 间接依赖 npm
rc-input-number 7.4.2 间接依赖 npm
google.golang.org/appengine v1.6.7 间接依赖 go
text-encoding-utf-8 1.0.2 间接依赖 npm
github.com/pkg/browser v0.0.0-20210115035449-ce105d075bb4 间接依赖 go
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da 间接依赖 go
github.com/google/uuid v1.3.0 间接依赖 go
fsevents 2.3.2 直接依赖 npm
xtend 4.0.2 间接依赖 npm
is-glob 4.0.3 间接依赖 npm
github.com/cpuguy83/go-md2man/v2 v2.0.2 间接依赖 go
regenerator-runtime 0.13.11 间接依赖 npm
@rc-component/trigger 1.5.2 间接依赖 npm
didyoumean 1.2.2 间接依赖 npm
glob-parent 6.0.2 间接依赖 npm
qrcode.react 3.1.0 间接依赖 npm
@rc-component/tour 1.8.0 间接依赖 npm
github.com/russross/blackfriday/v2 v2.1.0 间接依赖 go
rc-tree-select 5.7.0 间接依赖 npm
github.com/dustin/go-humanize v1.0.0 直接依赖 go
github.com/cheggaaa/pb/v3 v3.1.2 直接依赖 go
acorn-node 1.8.2 间接依赖 npm
has 1.0.3 间接依赖 npm
typescript 4.9.5 直接依赖 npm
clsx 1.2.1 间接依赖 npm
@remix-run/router 1.6.2 间接依赖 npm
@swc/core-linux-arm64-musl 1.3.40 直接依赖 npm
is-number 7.0.0 间接依赖 npm
github.com/mattn/go-isatty v0.0.17 间接依赖 go
rc-table 7.31.0 间接依赖 npm
rc-pagination 3.3.0 间接依赖 npm
postcss-nested 6.0.0 间接依赖 npm
github.com/mattn/go-runewidth v0.0.14 间接依赖 go
rc-upload 4.3.4 间接依赖 npm
@swc/core-darwin-x64 1.3.40 直接依赖 npm
@esbuild/linux-mips64el 0.16.17 直接依赖 npm
github.com/pelletier/go-toml/v2 v2.0.7 间接依赖 go
github.com/ugorji/go/codec v1.2.11 间接依赖 go
@emotion/hash 0.8.0 间接依赖 npm
classnames 2.3.2 间接依赖 npm
@swc/core-linux-x64-gnu 1.3.40 直接依赖 npm
github.com/spf13/jwalterweatherman v1.1.0 间接依赖 go
acorn 7.4.1 间接依赖 npm
github.com/hashicorp/hcl v1.0.0 间接依赖 go
@swc/core-linux-arm-gnueabihf 1.3.40 直接依赖 npm
anymatch 3.1.3 间接依赖 npm
react-lifecycles-compat 3.0.4 间接依赖 npm
@types/react-dom 18.0.11 直接依赖 npm
array-tree-filter 2.1.0 间接依赖 npm
@rc-component/mutate-observer 1.0.0 间接依赖 npm
fast-glob 3.2.12 间接依赖 npm
cloud.google.com/go v0.104.0 间接依赖 go
path-parse 1.0.7 间接依赖 npm
react-router-dom 6.11.2 直接依赖 npm
yaml 1.10.2 间接依赖 npm
rc-switch 4.0.0 间接依赖 npm
@remix-run/router 1.4.0 间接依赖 npm
queue-microtask 1.2.3 间接依赖 npm
golang.org/x/xerrors v0.0.0-20220907171357-04be3eba64a2 间接依赖 go
@ant-design/colors 7.0.0 间接依赖 npm
golang.org/x/sync v0.1.0 间接依赖 go
remixicon 2.5.0 直接依赖 npm
github.com/pkg/sftp v1.13.5 直接依赖 go
react-string-replace 0.4.4 间接依赖 npm
json2mq 0.2.0 间接依赖 npm
whatwg-fetch 2.0.4 间接依赖 npm
rc-dropdown 4.0.1 间接依赖 npm
picocolors 1.0.0 间接依赖 npm
github.com/golang/protobuf v1.5.2 间接依赖 go
(0)
上一篇 2023年10月30日
下一篇 2023年10月30日

相关推荐

  • benbusby/earthbound-themes 软件分析报告

    基础信息 项目名称:benbusby/earthbound-themes 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1716295531810652160/1716295536579575808 此报告由Mur…

    软件分析 2023年10月23日
    0
  • yamartino/pressure 软件分析报告

    基础信息 项目名称:yamartino/pressure 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721637126528110592/1721637126565859328 此报告由Murphysec提供…

    软件分析 2023年11月7日
    0
  • laixintao/myrc 软件分析报告

    基础信息 项目名称:laixintao/myrc 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1719630623236816896/1719630623316508672 此报告由Murphysec提供 漏洞列…

    软件分析 2023年11月1日
    0
  • ianhattendorf/autocomplete-ruby 软件分析报告

    基础信息 项目名称:ianhattendorf/autocomplete-ruby 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721270445855506432/1723875076279328768 此报…

    软件分析 2023年11月13日
    0
  • isaacplmann/ngx-contextmenu 软件分析报告

    基础信息 项目名称:isaacplmann/ngx-contextmenu 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721284781625868288/1726660348305956864 此报告由Mu…

    软件分析 2023年11月21日
    0