cosmos/cosmos-sdk 软件分析报告

基础信息

项目名称:cosmos/cosmos-sdk

项目徽章:

Security Status

仓库地址:https://github.com/pterodactyl/panel

检测报告地址:https://www.murphysec.com/console/report/1721107567727345664/1730823486286815232

此报告由Murphysec提供

漏洞列表

漏洞名称 漏洞类型 MPS编号 CVE编号 漏洞等级
nhooyr.io/websocket 存在拒绝服务漏洞 拒绝服务 MPS-2022-13514 高危

缺陷组件

组件名称 版本 最小修复版本 依赖关系 修复建议
nhooyr.io/websocket v1.8.6 1.8.7 间接依赖 建议修复

许可证风险

许可证类型 相关组件 许可证风险
BSD-3-Clause 56
Apache-2.0 99
MIT 81
ISC 6
MPL-2.0 12
BSD-2-Clause 7
BSD-2-Clause-Views 1

SBOM清单

组件名称 组件版本 是否直接依赖 仓库
google.golang.org/protobuf v1.31.0 直接依赖 go
google.golang.org/genproto/googleapis/rpc v0.0.0-20231016165738-49dd2c1f3d0b 间接依赖 go
github.com/go-logfmt/logfmt v0.6.0 间接依赖 go
golang.org/x/exp v0.0.0-20220722155223-a9213eeb770e 直接依赖 go
google.golang.org/genproto/googleapis/api v0.0.0-20231106174013-bbf56f31fb17 直接依赖 go
github.com/klauspost/compress v1.16.5 间接依赖 go
github.com/cosmos/cosmos-sdk v0.46.0-beta2.0.20231020102946-7421783eda5d 直接依赖 go
github.com/inconshreveable/mousetrap v1.1.0 间接依赖 go
github.com/ulikunitz/xz v0.5.11 间接依赖 go
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc 间接依赖 go
github.com/btcsuite/btcd/btcec/v2 v2.3.2 间接依赖 go
github.com/dvsekhvalnov/jose2go v1.5.0 间接依赖 go
cosmossdk.io/x/upgrade v0.1.0 直接依赖 go
github.com/gogo/googleapis v1.4.1 间接依赖 go
github.com/creachadair/atomicfile v0.3.2 直接依赖 go
cosmossdk.io/log v1.2.1 直接依赖 go
github.com/cockroachdb/logtags v0.0.0-20230118201751-21c54148d20b 间接依赖 go
google.golang.org/genproto/googleapis/rpc v0.0.0-20230822172742-b8732ec3820d 间接依赖 go
github.com/cenkalti/backoff/v4 v4.2.0 间接依赖 go
github.com/cockroachdb/errors v1.11.1 直接依赖 go
github.com/grpc-ecosystem/go-grpc-middleware v1.4.0 直接依赖 go
sigs.k8s.io/yaml v1.4.0 直接依赖 go
cosmossdk.io/math v1.2.0 直接依赖 go
github.com/manifoldco/promptui v0.9.0 直接依赖 go
github.com/cosmos/ics23/go v0.10.0 直接依赖 go
github.com/spf13/cast v1.5.1 间接依赖 go
cosmossdk.io/x/feegrant v0.0.0-20230613133644-0a778132a60f 直接依赖 go
golang.org/x/exp v0.0.0-20230811145659-89c5cff77bcb 间接依赖 go
github.com/cometbft/cometbft-db v0.8.0 间接依赖 go
github.com/cockroachdb/apd/v3 v3.2.0 间接依赖 go
github.com/google/uuid v1.4.0 间接依赖 go
github.com/sourcegraph/conc v0.3.0 间接依赖 go
google.golang.org/genproto v0.0.0-20231012201019-e917dd12ba7a 间接依赖 go
golang.org/x/text v0.12.0 间接依赖 go
github.com/cockroachdb/apd/v2 v2.0.2 直接依赖 go
github.com/hashicorp/yamux v0.1.1 间接依赖 go
github.com/aws/aws-sdk-go v1.45.25 间接依赖 go
github.com/google/gofuzz v1.2.0 直接依赖 go
cosmossdk.io/api v0.7.2 直接依赖 go
github.com/99designs/go-keychain v0.0.0-20191008050251-8e49817e8af4 间接依赖 go
github.com/pkg/errors v0.9.1 直接依赖 go
github.com/golang/mock v1.6.0 直接依赖 go
github.com/jmespath/go-jmespath v0.4.0 间接依赖 go
cosmossdk.io/store v1.0.1 直接依赖 go
github.com/creachadair/tomledit v0.0.25 直接依赖 go
cosmossdk.io/x/gov v0.0.0-20231113122742-912390d5fc4a 直接依赖 go
github.com/iancoleman/strcase v0.3.0 直接依赖 go
github.com/google/s2a-go v0.1.7 间接依赖 go
google.golang.org/grpc v1.59.0 直接依赖 go
github.com/go-kit/kit v0.12.0 间接依赖 go
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da 间接依赖 go
rsc.io/qr v0.2.0 间接依赖 go
nhooyr.io/websocket v1.8.6 间接依赖 go
github.com/gorilla/mux v1.8.1 直接依赖 go
github.com/stretchr/testify v1.8.4 直接依赖 go
github.com/prometheus/client_golang v1.17.0 直接依赖 go
github.com/danieljoos/wincred v1.2.0 间接依赖 go
cosmossdk.io/x/group v0.0.0-00010101000000-000000000000 直接依赖 go
github.com/hdevalence/ed25519consensus v0.1.0 直接依赖 go
github.com/cosmos/ledger-cosmos-go v0.13.3 直接依赖 go
google.golang.org/api v0.149.0 间接依赖 go
github.com/fsnotify/fsnotify v1.6.0 间接依赖 go
github.com/fatih/color v1.15.0 间接依赖 go
github.com/hashicorp/go-immutable-radix v1.0.0 间接依赖 go
github.com/rcrowley/go-metrics v0.0.0-20201227073835-cf1acfcdf475 间接依赖 go
github.com/godbus/dbus v0.0.0-20190726142602-4481cbc300e2 间接依赖 go
github.com/hashicorp/go-cleanhttp v0.5.2 直接依赖 go
github.com/matttproud/golang_protobuf_extensions/v2 v2.0.0 间接依赖 go
golang.org/x/text v0.14.0 间接依赖 go
github.com/chzyer/readline v1.5.1 直接依赖 go
github.com/mitchellh/mapstructure v1.5.0 间接依赖 go
cosmossdk.io/x/distribution v0.0.0-20230925135524-a1bc045b3190 直接依赖 go
github.com/petermattis/goid v0.0.0-20231126143041-f558c26febf5 间接依赖 go
github.com/bufbuild/protocompile v0.6.0 间接依赖 go
golang.org/x/term v0.15.0 间接依赖 go
github.com/rs/cors v1.8.3 间接依赖 go
cosmossdk.io/api v0.7.3-0.20231113122742-912390d5fc4a 直接依赖 go
cloud.google.com/go/compute/metadata v0.2.3 间接依赖 go
cloud.google.com/go/compute v1.23.3 间接依赖 go
github.com/gofrs/uuid v4.4.0+incompatible 间接依赖 go
nhooyr.io/websocket v1.8.7 间接依赖 go
github.com/99designs/keyring v1.2.1 直接依赖 go
github.com/cosmos/gogoproto v1.4.11 直接依赖 go
go.uber.org/multierr v1.11.0 间接依赖 go
gopkg.in/yaml.v3 v3.0.1 直接依赖 go
github.com/zondax/hid v0.9.2 间接依赖 go
github.com/cenkalti/backoff/v4 v4.2.1 间接依赖 go
golang.org/x/net v0.17.0 间接依赖 go
github.com/99designs/keyring v1.2.2 间接依赖 go
github.com/go-kit/kit v0.13.0 间接依赖 go
cosmossdk.io/simapp v0.0.0-00010101000000-000000000000 直接依赖 go
github.com/hashicorp/go-hclog v1.5.0 间接依赖 go
golang.org/x/sys v0.13.0 间接依赖 go
github.com/getsentry/sentry-go v0.25.0 间接依赖 go
github.com/cosmos/btcutil v1.0.5 直接依赖 go
github.com/sagikazarmark/slog-shim v0.1.0 间接依赖 go
cosmossdk.io/simapp v0.0.0-20230309163709-87da587416ba 直接依赖 go
github.com/spf13/cast v1.6.0 直接依赖 go
github.com/cosmos/cosmos-sdk v0.51.0 直接依赖 go
google.golang.org/genproto/googleapis/api v0.0.0-20231002182017-d307bd883b97 直接依赖 go
github.com/hashicorp/hcl v1.0.0 间接依赖 go
github.com/gorilla/websocket v1.5.0 间接依赖 go
github.com/mitchellh/go-homedir v1.1.0 间接依赖 go
golang.org/x/crypto v0.16.0 直接依赖 go
github.com/cucumber/common/messages/go/v19 v19.1.2 间接依赖 go
filippo.io/edwards25519 v1.0.0 间接依赖 go
golang.org/x/sync v0.5.0 直接依赖 go
github.com/oklog/run v1.1.0 间接依赖 go
github.com/regen-network/gocuke v0.6.3 直接依赖 go
github.com/prometheus/client_model v0.5.0 间接依赖 go
github.com/grpc-ecosystem/grpc-gateway v1.16.0 直接依赖 go
github.com/opencontainers/runc v1.1.5 间接依赖 go
golang.org/x/xerrors v0.0.0-20231012003039-104605ab7028 间接依赖 go
github.com/cosmos/cosmos-db v1.0.0 直接依赖 go
github.com/onsi/gomega v1.27.4 间接依赖 go
github.com/mattn/go-isatty v0.0.20 直接依赖 go
github.com/hashicorp/go-safetemp v1.0.0 间接依赖 go
github.com/desertbit/timer v0.0.0-20180107155436-c41aec40b27f 间接依赖 go
cosmossdk.io/client/v2 v2.0.0-20231020102946-7421783eda5d 直接依赖 go
github.com/klauspost/compress v1.17.2 间接依赖 go
github.com/cosmos/cosmos-proto v1.0.0-beta.3 直接依赖 go
github.com/decred/dcrd/dcrec/secp256k1/v4 v4.2.0 直接依赖 go
github.com/huandu/skiplist v1.2.0 直接依赖 go
github.com/kr/pretty v0.3.1 间接依赖 go
golang.org/x/net v0.19.0 间接依赖 go
golang.org/x/sys v0.11.0 间接依赖 go
github.com/getsentry/sentry-go v0.23.0 间接依赖 go
cosmossdk.io/errors v1.0.0 直接依赖 go
github.com/oasisprotocol/curve25519-voi v0.0.0-20230904125328-1f23a7beb09a 间接依赖 go
github.com/cockroachdb/redact v1.1.5 间接依赖 go
cosmossdk.io/x/staking v0.0.0-00010101000000-000000000000 直接依赖 go
cosmossdk.io/x/mint v0.0.0-00010101000000-000000000000 直接依赖 go
github.com/improbable-eng/grpc-web v0.15.0 直接依赖 go
github.com/dgraph-io/ristretto v0.1.1 间接依赖 go
github.com/spf13/afero v1.10.0 间接依赖 go
github.com/cometbft/cometbft v0.38.2 直接依赖 go
github.com/prometheus/common v0.45.0 直接依赖 go
cloud.google.com/go/storage v1.33.0 间接依赖 go
github.com/sasha-s/go-deadlock v0.3.1 间接依赖 go
github.com/cosmos/cosmos-sdk v0.50.1 间接依赖 go
github.com/nxadm/tail v1.4.8 间接依赖 go
github.com/pmezard/go-difflib v1.0.0 间接依赖 go
github.com/opencontainers/image-spec v1.1.0-rc2.0.20221005185240-3a7f492d3f1b 间接依赖 go
cosmossdk.io/collections v0.4.0 直接依赖 go
github.com/cockroachdb/tokenbucket v0.0.0-20230807174530-cc333fc44b06 间接依赖 go
github.com/googleapis/gax-go/v2 v2.12.0 间接依赖 go
github.com/syndtr/goleveldb v1.0.1-0.20210819022825-2ae1ddf74ef7 间接依赖 go
cosmossdk.io/x/protocolpool v0.0.0-20230925135524-a1bc045b3190 直接依赖 go
github.com/bits-and-blooms/bitset v1.10.0 直接依赖 go
github.com/dgryski/go-farm v0.0.0-20200201041132-a6ae2369ad13 间接依赖 go
google.golang.org/genproto/googleapis/rpc v0.0.0-20231127180814-3a041ad873d4 间接依赖 go
cosmossdk.io/x/slashing v0.0.0-00010101000000-000000000000 直接依赖 go
go.opencensus.io v0.24.0 间接依赖 go
cloud.google.com/go/iam v1.1.5 间接依赖 go
github.com/spf13/pflag v1.0.5 直接依赖 go
github.com/rs/zerolog v1.30.0 直接依赖 go
cosmossdk.io/x/accounts v0.0.0-20231013072015-ec9bcc41ef9c 直接依赖 go
github.com/syndtr/goleveldb v1.0.1-0.20220721030215-126854af5e6d 间接依赖 go
gopkg.in/ini.v1 v1.67.0 间接依赖 go
github.com/cespare/xxhash v1.1.0 间接依赖 go
github.com/go-kit/log v0.2.1 间接依赖 go
github.com/subosito/gotenv v1.6.0 间接依赖 go
github.com/cockroachdb/pebble v0.0.0-20231129003907-ce7560a81fb6 间接依赖 go
github.com/otiai10/copy v1.14.0 直接依赖 go
golang.org/x/exp v0.0.0-20221205204356-47842c84f3db 直接依赖 go
cosmossdk.io/x/upgrade v0.0.0-20230613133644-0a778132a60f 直接依赖 go
github.com/cockroachdb/pebble v0.0.0-20231102162011-844f0582c2eb 直接依赖 go
github.com/kr/text v0.2.0 间接依赖 go
cosmossdk.io/depinject v1.0.0-alpha.4 直接依赖 go
gotest.tools/v3 v3.5.1 直接依赖 go
pgregory.net/rapid v1.1.0 直接依赖 go
cosmossdk.io/x/circuit v0.0.0-20230613133644-0a778132a60f 直接依赖 go
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 间接依赖 go
github.com/prometheus/procfs v0.12.0 间接依赖 go
github.com/mtibben/percent v0.2.1 间接依赖 go
github.com/cosmos/iavl v1.0.0 直接依赖 go
github.com/hashicorp/golang-lru v1.0.2 直接依赖 go
github.com/google/btree v1.1.2 间接依赖 go
cosmossdk.io/x/authz v0.0.0-00010101000000-000000000000 直接依赖 go
github.com/hashicorp/golang-lru v0.5.0 间接依赖 go
github.com/rs/cors v1.10.0 间接依赖 go
github.com/danieljoos/wincred v1.1.2 间接依赖 go
cosmossdk.io/tools/confix v0.0.0-20230613133644-0a778132a60f 直接依赖 go
github.com/google/go-cmp v0.6.0 直接依赖 go
github.com/jhump/protoreflect v1.15.3 直接依赖 go
google.golang.org/appengine v1.6.8 间接依赖 go
github.com/minio/highwayhash v1.0.2 间接依赖 go
github.com/prometheus/procfs v0.11.1 间接依赖 go
github.com/lib/pq v1.10.7 间接依赖 go
github.com/emicklei/dot v1.6.0 间接依赖 go
github.com/pelletier/go-toml/v2 v2.1.0 直接依赖 go
golang.org/x/sys v0.15.0 间接依赖 go
github.com/spf13/cobra v1.8.0 直接依赖 go
github.com/golang/protobuf v1.5.3 直接依赖 go
github.com/cosmos/gogogateway v1.2.0 直接依赖 go
github.com/linxGnu/grocksdb v1.8.6 直接依赖 go
cosmossdk.io/x/tx v0.12.0 直接依赖 go
github.com/petermattis/goid v0.0.0-20180202154549-b0b1615b78e5 间接依赖 go
cosmossdk.io/core v0.12.1-0.20231114100755-569e3ff6a0d7 直接依赖 go
github.com/cucumber/tag-expressions/go/v5 v5.0.2 间接依赖 go
github.com/mitchellh/go-testing-interface v1.14.1 间接依赖 go
github.com/hashicorp/go-metrics v0.5.3 直接依赖 go
github.com/decred/dcrd/dcrec/secp256k1/v4 v4.0.1 间接依赖 go
golang.org/x/sync v0.4.0 间接依赖 go
github.com/libp2p/go-buffer-pool v0.1.0 间接依赖 go
github.com/hashicorp/go-plugin v1.5.2 间接依赖 go
cosmossdk.io/x/evidence v0.0.0-20230613133644-0a778132a60f 直接依赖 go
golang.org/x/exp v0.0.0-20231006140011-7918f672742d 直接依赖 go
github.com/mattn/go-colorable v0.1.13 间接依赖 go
github.com/dustin/go-humanize v1.0.1 间接依赖 go
golang.org/x/exp v0.0.0-20230817173708-d852ddb80c63 直接依赖 go
github.com/magiconair/properties v1.8.7 直接依赖 go
github.com/mdp/qrterminal/v3 v3.2.0 直接依赖 go
github.com/klauspost/compress v1.17.3 间接依赖 go
github.com/gsterjov/go-libsecret v0.0.0-20161001094733-a6f4afe4910c 间接依赖 go
golang.org/x/oauth2 v0.13.0 间接依赖 go
github.com/hashicorp/go-version v1.6.0 间接依赖 go
github.com/dgraph-io/badger/v2 v2.2007.4 间接依赖 go
github.com/hashicorp/go-immutable-radix v1.3.1 间接依赖 go
github.com/cosmos/go-bip39 v1.0.0 直接依赖 go
github.com/hashicorp/go-getter v1.7.3 直接依赖 go
github.com/davecgh/go-spew v1.1.1 间接依赖 go
github.com/felixge/httpsnoop v1.0.4 间接依赖 go
github.com/gorilla/handlers v1.5.2 直接依赖 go
github.com/cosmos/cosmos-sdk v0.46.0-beta2.0.20230614103911-b3da8bb4e801 直接依赖 go
golang.org/x/exp v0.0.0-20231127185646-65229373498e 直接依赖 go
cloud.google.com/go v0.110.10 间接依赖 go
github.com/golang/glog v1.1.2 间接依赖 go
github.com/google/orderedcode v0.0.1 间接依赖 go
cosmossdk.io/x/nft v0.0.0-20230613133644-0a778132a60f 直接依赖 go
github.com/tidwall/btree v1.7.0 直接依赖 go
github.com/cucumber/messages/go/v21 v21.0.1 间接依赖 go
github.com/rs/zerolog v1.31.0 直接依赖 go
github.com/armon/go-metrics v0.4.1 间接依赖 go
github.com/cockroachdb/pebble v0.0.0-20230525220056-bb4fc9527b3b 间接依赖 go
github.com/zondax/ledger-go v0.14.3 间接依赖 go
github.com/kr/pretty v0.3.0 间接依赖 go
cosmossdk.io/x/auth v0.0.0-00010101000000-000000000000 直接依赖 go
github.com/oasisprotocol/curve25519-voi v0.0.0-20220708102147-0a8a51822cae 间接依赖 go
github.com/mattn/go-sqlite3 v1.14.18 直接依赖 go
github.com/cucumber/gherkin/go/v26 v26.2.0 间接依赖 go
github.com/golang/snappy v0.0.4 间接依赖 go
github.com/rogpeppe/go-internal v1.8.1 间接依赖 go
github.com/prometheus/client_model v0.4.1-0.20230718164431-9a2bf3000d16 间接依赖 go
github.com/sagikazarmark/locafero v0.3.0 间接依赖 go
cosmossdk.io/core v0.12.0 直接依赖 go
github.com/rogpeppe/go-internal v1.11.0 间接依赖 go
cosmossdk.io/x/bank v0.0.0-00010101000000-000000000000 直接依赖 go
github.com/cenkalti/backoff/v4 v4.1.3 间接依赖 go
cosmossdk.io/core v0.11.0 直接依赖 go
github.com/DataDog/zstd v1.5.5 间接依赖 go
cosmossdk.io/client/v2 v2.0.0-20230630094428-02b760776860 直接依赖 go
github.com/cespare/xxhash/v2 v2.2.0 间接依赖 go
github.com/googleapis/enterprise-certificate-proxy v0.3.2 间接依赖 go
go.etcd.io/bbolt v1.3.7 间接依赖 go
github.com/gogo/protobuf v1.3.2 间接依赖 go
golang.org/x/text v0.13.0 间接依赖 go
github.com/bgentry/speakeasy v0.1.1-0.20220910012023-760eaf8b6816 直接依赖 go
google.golang.org/genproto v0.0.0-20231120223509-83a465c0220f 间接依赖 go
github.com/spf13/viper v1.17.0 直接依赖 go
github.com/bgentry/go-netrc v0.0.0-20140422174119-9fd32a8b3d3d 间接依赖 go
github.com/jmhodges/levigo v1.0.0 间接依赖 go
github.com/tendermint/go-amino v0.16.0 直接依赖 go
gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c 间接依赖 go
cosmossdk.io/x/gov v0.0.0-20230925135524-a1bc045b3190 直接依赖 go
github.com/beorn7/perks v1.0.1 间接依赖 go
github.com/onsi/gomega v1.20.0 间接依赖 go
(0)
上一篇 2023年12月2日
下一篇 2023年12月2日

相关推荐

  • xdspacelab/openvslam 软件分析报告

    基础信息 项目名称:xdspacelab/openvslam 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1724666507608678400/1724666507671592960 此报告由Murphysec…

    软件分析 2023年11月15日
    0
  • apache/logging-log4j-audit 软件分析报告

    基础信息 项目名称:apache/logging-log4j-audit 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1730002207845605376/1730002207883354112 此报告由Mur…

    软件分析 2023年11月30日
    0
  • aliyun/aliyun-openapi-php-sdk 软件分析报告

    基础信息 项目名称:aliyun/aliyun-openapi-php-sdk 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1715717570027978752/1715717570090893312 此报告由…

    软件分析 2023年10月23日
    0
  • yuri2peter/contextMenu 软件分析报告

    基础信息 项目名称:yuri2peter/contextMenu 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721682473661042688/1721682473812037632 此报告由Murphys…

    软件分析 2023年11月7日
    0
  • jolie/jolie 软件分析报告

    基础信息 项目名称:jolie/jolie 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721317546673393664/1724273667128909824 此报告由Murphysec提供 漏洞列表 漏…

    软件分析 2023年11月14日
    0