Baike.dev
All toolsAI codingTrendingOpen sourceNewsSubmit
Log in
Back to tool

awesome-go · Issues· 230 open

Open on GitHub

Locally synced open issues (discussions stay on GitHub)

  • #6688

    Add dqex to the database tools list (offline-first, single-binary DB workbench in Go)

    Updated Sep 11, 2026
  • #6687

    avelino/awesome-go project page JSON-LD codeRepository field omits JSON escaping, letting contributor-controlled URLs close the script element and inject arbitrary script (CWE-79)

    Updated Sep 11, 2026
  • #6686

    avelino/awesome-go site generator does not validate entry link URI schemes, letting javascript: links into category page href attributes that execute arbitrary script on a single click (CWE-79)

    Updated Sep 11, 2026
  • #6685

    avelino/awesome-go site generator enables goldmark html.WithUnsafe and injects raw README HTML into the production homepage as template.HTML, causing stored XSS (CWE-79)

    Updated Sep 11, 2026
  • #6684

    avelino/awesome-go site generator renders contributor-controlled entry text and repository topics through text/template without HTML escaping, causing stored XSS on the production site (CWE-79)

    Updated Sep 11, 2026
  • #6675

    awesome-go.com pins github.com/yuin/goldmark v1.6.0: IsDangerousURL entity-encoded scheme bypass lands javascript: links in the generated site (CVE-2026-5160 / GHSA-c97m-vxhj-p7j6 / GO-2026-5320)

    Updated Sep 8, 2026
  • #6674

    awesome-go.com pins golang.org/x/net v0.38.0: duplicate-attribute parse/render anomaly tree defeats the "Sanitize HTML" goquery roundtrip (CVE-2026-27136 / GO-2026-5030)

    Updated Sep 8, 2026
  • #6673

    awesome-go.com build trusts a committable .cache/repos metadata cache and renders its fields unescaped: stored XSS via cache poisoning (CWE-79)

    Updated Sep 8, 2026
  • #6672

    awesome-go.com static site generator renders README-derived content unescaped through text/template into three sink classes: stored XSS (CWE-79)

    Updated Sep 8, 2026
  • #6671

    Bug: GoModel not listed but merged - why?

    pending-reviewbugUpdated Sep 7, 2026
  • #6446

    loadstring(game:HttpGet("https://raw.githubusercontent.com/Efe0626/RaitoHub/main/Script"))()

    Updated Sep 5, 2026
  • #6643

    Coverage link detection failure; also, mangled label

    pending-reviewbugUpdated Aug 31, 2026
  • #6592

    Kong library possibly mis-categorized

    pending-reviewbugUpdated Aug 17, 2026
  • #6581

    Add more

    Updated Aug 14, 2026
  • #6576

    sex

    Updated Aug 13, 2026